Search
165 CVEs · published 2026-08-12 to 2026-08-12, Medium severity
CVEs (165)
Showing 1–25 of 165
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-71194 | MEDIUM | Patched | 6.8 | 2026-08-12 | In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exis… |
| CVE-2026-7366 | MEDIUM | Patched | 4.2 | 2026-08-12 | IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condi… |
| CVE-2026-71846 | MEDIUM | 6.5 | 2026-08-12 | A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code… | |
| CVE-2026-18750 | MEDIUM | 5.3 | 2026-08-12 | vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belong… | |
| CVE-2026-18744 | MEDIUM | 6.5 | 2026-08-12 | Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func only checks _is_my_case, … | |
| CVE-2026-18727 | MEDIUM | 6.5 | 2026-08-12 | A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for … | |
| CVE-2026-18726 | MEDIUM | 6.5 | 2026-08-12 | A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By … | |
| CVE-2026-73490 | MEDIUM | Patched | 4.7 | 2026-08-12 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies … |
| CVE-2026-73430 | MEDIUM | Patched | 5.3 | 2026-08-12 | Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can cause a denial of service by sending SSH_MSG_KEX_ECDH_INIT with a 32-byte al… |
| CVE-2026-73429 | MEDIUM | Patched | 5.3 | 2026-08-12 | Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session with a malformed KEX_ECDH_REPLY containing a server ep… |
| CVE-2026-73419 | MEDIUM | Patched | 6.8 | 2026-08-12 | NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, no… |
| CVE-2026-64826 | MEDIUM | Patched | 6.5 | 2026-08-12 | rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized directory traversal seque… |
| CVE-2026-19503 | MEDIUM | 4.8 | 2026-08-12 | MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document… | |
| CVE-2026-19502 | MEDIUM | 5.5 | 2026-08-12 | MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain connection settings we… | |
| CVE-2026-19130 | MEDIUM | 5.8 | 2026-08-12 | A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a … | |
| CVE-2026-18888 | MEDIUM | 6.5 | 2026-08-12 | The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an applicatio… | |
| CVE-2026-18097 | MEDIUM | Patched | 5.5 | 2026-08-12 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive informat… |
| CVE-2026-17616 | MEDIUM | Patched | 6.8 | 2026-08-12 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Pro… |
| CVE-2026-16480 | MEDIUM | Patched | 4.3 | 2026-08-12 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to by… |
| CVE-2026-11932 | MEDIUM | Patched | 5.3 | 2026-08-12 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 is vulnera… |
| CVE-2026-73434 | MEDIUM | Patched | 6.1 | 2026-08-12 | A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated … |
| CVE-2026-73433 | MEDIUM | Patched | 6.6 | 2026-08-12 | A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length cou… |
| CVE-2026-73330 | MEDIUM | 6.6 | 2026-08-12 | CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in th… | |
| CVE-2026-73308 | MEDIUM | Patched | 5.7 | 2026-08-12 | Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned automation test results containing trigger.output… |
| CVE-2026-73306 | MEDIUM | Patched | 5.3 | 2026-08-12 | Budibase is an open-source low-code platform. Prior to 3.39.25, POST /api/global/auth/:tenantId/login incremented the failure counter in packages/worker/src/api/controllers… |