Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

165 CVEs · published 2026-08-12 to 2026-08-12, Medium severity

CVEs (165)

Showing 1–25 of 165

CVE ID Severity Patch CVSS Published Description
CVE-2026-71194 MEDIUM Patched 6.8 2026-08-12 In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exis…
CVE-2026-7366 MEDIUM Patched 4.2 2026-08-12 IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condi…
CVE-2026-71846 MEDIUM 6.5 2026-08-12 A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code…
CVE-2026-18750 MEDIUM 5.3 2026-08-12 vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belong…
CVE-2026-18744 MEDIUM 6.5 2026-08-12 Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func only checks _is_my_case, …
CVE-2026-18727 MEDIUM 6.5 2026-08-12 A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for …
CVE-2026-18726 MEDIUM 6.5 2026-08-12 A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By …
CVE-2026-73490 MEDIUM Patched 4.7 2026-08-12 Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies …
CVE-2026-73430 MEDIUM Patched 5.3 2026-08-12 Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can cause a denial of service by sending SSH_MSG_KEX_ECDH_INIT with a 32-byte al…
CVE-2026-73429 MEDIUM Patched 5.3 2026-08-12 Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session with a malformed KEX_ECDH_REPLY containing a server ep…
CVE-2026-73419 MEDIUM Patched 6.8 2026-08-12 NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, no…
CVE-2026-64826 MEDIUM Patched 6.5 2026-08-12 rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized directory traversal seque…
CVE-2026-19503 MEDIUM 4.8 2026-08-12 MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document…
CVE-2026-19502 MEDIUM 5.5 2026-08-12 MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain connection settings we…
CVE-2026-19130 MEDIUM 5.8 2026-08-12 A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a …
CVE-2026-18888 MEDIUM 6.5 2026-08-12 The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an applicatio…
CVE-2026-18097 MEDIUM Patched 5.5 2026-08-12 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive informat…
CVE-2026-17616 MEDIUM Patched 6.8 2026-08-12 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Pro…
CVE-2026-16480 MEDIUM Patched 4.3 2026-08-12 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to by…
CVE-2026-11932 MEDIUM Patched 5.3 2026-08-12 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 is vulnera…
CVE-2026-73434 MEDIUM Patched 6.1 2026-08-12 A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated …
CVE-2026-73433 MEDIUM Patched 6.6 2026-08-12 A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length cou…
CVE-2026-73330 MEDIUM 6.6 2026-08-12 CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in th…
CVE-2026-73308 MEDIUM Patched 5.7 2026-08-12 Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned automation test results containing trigger.output…
CVE-2026-73306 MEDIUM Patched 5.3 2026-08-12 Budibase is an open-source low-code platform. Prior to 3.39.25, POST /api/global/auth/:tenantId/login incremented the failure counter in packages/worker/src/api/controllers…