Search
47 CVEs · published 2026-08-12 to 2026-08-12, Critical severity
CVEs (47)
Showing 1–25 of 47
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-71193 | CRITICAL | Patched | 9.6 | 2026-08-12 | In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authent… |
| CVE-2026-49481 | CRITICAL | 9.6 | 2026-08-12 | UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of u… | |
| CVE-2026-73519 | CRITICAL | Patched | 9.8 | 2026-08-12 | WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauth… |
| CVE-2026-73501 | CRITICAL | Patched | 9.1 | 2026-08-12 | kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil Authentic… |
| CVE-2026-71471 | CRITICAL | 9.0 | 2026-08-12 | A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), c… | |
| CVE-2026-18749 | CRITICAL | 9.8 | 2026-08-12 | The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been mar… | |
| CVE-2024-27253 | CRITICAL | 10.0 | 2026-08-12 | IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities. | |
| CVE-2026-66898 | CRITICAL | 9.9 | 2026-08-12 | A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup a… | |
| CVE-2026-19001 | CRITICAL | 9.8 | 2026-08-12 | The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a… | |
| CVE-2026-73269 | CRITICAL | 9.9 | 2026-08-12 | A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creatio… | |
| CVE-2026-73268 | CRITICAL | 9.9 | 2026-08-12 | A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject… | |
| CVE-2026-72508 | CRITICAL | 9.9 | 2026-08-12 | A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to pe… | |
| CVE-2026-63300 | CRITICAL | 9.9 | 2026-08-12 | An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permiss… | |
| CVE-2026-63299 | CRITICAL | 9.9 | 2026-08-12 | An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource lim… | |
| CVE-2026-63298 | CRITICAL | 9.9 | 2026-08-12 | An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configurat… | |
| CVE-2026-63297 | CRITICAL | 9.9 | 2026-08-12 | An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during… | |
| CVE-2026-63296 | CRITICAL | 9.9 | 2026-08-12 | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to… | |
| CVE-2026-63294 | CRITICAL | 9.9 | 2026-08-12 | A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup arc… | |
| CVE-2026-63293 | CRITICAL | 9.9 | 2026-08-12 | A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archiv… | |
| CVE-2026-62420 | CRITICAL | 9.9 | 2026-08-12 | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When … | |
| CVE-2026-19656 | CRITICAL | 9.9 | 2026-08-12 | ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissi… | |
| CVE-2026-17083 | CRITICAL | 9.8 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow. | |
| CVE-2026-73300 | CRITICAL | Patched | 9.6 | 2026-08-12 | Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution o… |
| CVE-2026-73299 | CRITICAL | Patched | 10.0 | 2026-08-12 | Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies… |
| CVE-2026-17276 | CRITICAL | Patched | 9.6 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads. |