Search
33 CVEs · published 2026-08-04 to 2026-08-04, Critical severity
CVEs (33)
Showing 1–25 of 33
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-45537 | CRITICAL | Patched | 9.1 | 2026-08-04 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI comp… |
| CVE-2026-45100 | CRITICAL | Patched | 9.1 | 2026-08-04 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta contain a buffer overflow in the {s.b64encode} strin… |
| CVE-2026-70554 | CRITICAL | 9.8 | 2026-08-04 | MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in … | |
| CVE-2026-67979 | CRITICAL | 9.1 | 2026-08-04 | Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shar… | |
| CVE-2026-66902 | CRITICAL | Patched | 9.8 | 2026-08-04 | Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call. The Pluggable subclass reads credential_… |
| CVE-2026-45538 | CRITICAL | 9.8 | 2026-08-04 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP message with a header name longer than 255 bytes causes… | |
| CVE-2026-70553 | CRITICAL | 9.8 | 2026-08-04 | MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by sub… | |
| CVE-2026-70552 | CRITICAL | 9.8 | 2026-08-04 | MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints b… | |
| CVE-2026-69703 | CRITICAL | 9.8 | 2026-08-04 | Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass sessio… | |
| CVE-2026-49435 | CRITICAL | 9.8 | 2026-08-04 | Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execut… | |
| CVE-2026-0163 | CRITICAL | 9.8 | 2026-08-04 | In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execu… | |
| CVE-2017-20242 | CRITICAL | Patched | 9.8 | 2026-08-04 | Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpo… |
| CVE-2017-20241 | CRITICAL | Patched | 9.8 | 2026-08-04 | Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoi… |
| CVE-2026-24254 | CRITICAL | Patched | 9.8 | 2026-08-04 | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vuln… |
| CVE-2026-63456 | CRITICAL | 9.8 | 2026-08-04 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechani… | |
| CVE-2026-63455 | CRITICAL | 9.8 | 2026-08-04 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechani… | |
| CVE-2025-29296 | CRITICAL | 9.8 | 2026-08-04 | H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100… | |
| CVE-2026-69110 | CRITICAL | Patched | 9.1 | 2026-08-04 | OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static… |
| CVE-2026-69098 | CRITICAL | 9.8 | 2026-08-04 | kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary P… | |
| CVE-2026-25289 | CRITICAL | 9.6 | 2026-08-04 | Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values. | |
| CVE-2026-61515 | CRITICAL | 9.8 | 2026-08-04 | Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating s… | |
| CVE-2026-61514 | CRITICAL | 9.8 | 2026-08-04 | Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sendi… | |
| CVE-2026-10050 | CRITICAL | Patched | 9.1 | 2026-08-04 | In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HT… |
| CVE-2026-15721 | CRITICAL | Patched | 9.8 | 2026-08-04 | Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This iss… |
| CVE-2026-14804 | CRITICAL | Patched | 9.1 | 2026-08-04 | Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within… |