Search
151 CVEs · published 2026-08-12 to 2026-08-12, High severity
CVEs (151)
Showing 1–25 of 151
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-47717 | HIGH | 7.5 | 2026-08-12 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuratio… | |
| CVE-2026-73498 | HIGH | Patched | 7.7 | 2026-08-12 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplie… |
| CVE-2026-73495 | HIGH | Patched | 7.4 | 2026-08-12 | blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42, blaze-server can merge HTTP/1.1 chunked-body trail… |
| CVE-2026-73493 | HIGH | Patched | 7.5 | 2026-08-12 | Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incom… |
| CVE-2026-71473 | HIGH | 8.5 | 2026-08-12 | A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to… | |
| CVE-2026-71469 | HIGH | 7.5 | 2026-08-12 | A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent … | |
| CVE-2026-19003 | HIGH | 7.8 | 2026-08-12 | A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated… | |
| CVE-2026-17485 | HIGH | 8.2 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow. | |
| CVE-2026-10534 | HIGH | Patched | 8.4 | 2026-08-12 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser. |
| CVE-2026-73418 | HIGH | Patched | 7.5 | 2026-08-12 | NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and… |
| CVE-2026-65370 | HIGH | Patched | 7.5 | 2026-08-12 | ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. This vulnerability is addressed in servicetalk version… |
| CVE-2026-19654 | HIGH | Patched | 7.5 | 2026-08-12 | A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an i… |
| CVE-2026-19004 | HIGH | 8.1 | 2026-08-12 | An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this is… | |
| CVE-2026-19002 | HIGH | 8.1 | 2026-08-12 | A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client applicati… | |
| CVE-2026-16695 | HIGH | Patched | 7.8 | 2026-08-12 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an … |
| CVE-2026-16033 | HIGH | 8.5 | 2026-08-12 | A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD f… | |
| CVE-2026-14866 | HIGH | Patched | 7.7 | 2026-08-12 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore. |
| CVE-2026-13622 | HIGH | 8.8 | 2026-08-12 | A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launch… | |
| CVE-2026-13476 | HIGH | Patched | 7.3 | 2026-08-12 | IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to im… |
| CVE-2026-13433 | HIGH | Patched | 8.3 | 2026-08-12 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could… |
| CVE-2026-13367 | HIGH | 7.8 | 2026-08-12 | IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility. | |
| CVE-2026-13105 | HIGH | Patched | 8.8 | 2026-08-12 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration. |
| CVE-2026-13094 | HIGH | Patched | 7.8 | 2026-08-12 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configura… |
| CVE-2026-10543 | HIGH | Patched | 8.2 | 2026-08-12 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query. |
| CVE-2026-73406 | HIGH | Patched | 7.5 | 2026-08-12 | Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and ten… |