Search
442 CVEs · published 2026-08-12 to 2026-08-12
CVEs (442)
Showing 1–25 of 442
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-71194 | MEDIUM | Patched | 6.8 | 2026-08-12 | In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exis… |
| CVE-2026-71193 | CRITICAL | Patched | 9.6 | 2026-08-12 | In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authent… |
| CVE-2026-49481 | CRITICAL | 9.6 | 2026-08-12 | UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of u… | |
| CVE-2026-47718 | NONE | — | 2026-08-12 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read… | |
| CVE-2026-47717 | HIGH | 7.5 | 2026-08-12 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuratio… | |
| CVE-2026-15424 | NONE | — | 2026-08-12 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-15141 | NONE | — | 2026-08-12 | The web interface of the affected device relies on the HTTP referrer header as part of request validation. Requests containing empty Referer value, or omitting the Referer… | |
| CVE-2026-7366 | MEDIUM | Patched | 4.2 | 2026-08-12 | IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condi… |
| CVE-2026-73519 | CRITICAL | Patched | 9.8 | 2026-08-12 | WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauth… |
| CVE-2026-73501 | CRITICAL | Patched | 9.1 | 2026-08-12 | kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil Authentic… |
| CVE-2026-73500 | NONE | Patched | — | 2026-08-12 | etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listen… |
| CVE-2026-73499 | NONE | Patched | — | 2026-08-12 | etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission on a single exact ke… |
| CVE-2026-73498 | HIGH | Patched | 7.7 | 2026-08-12 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplie… |
| CVE-2026-73495 | HIGH | Patched | 7.4 | 2026-08-12 | blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42, blaze-server can merge HTTP/1.1 chunked-body trail… |
| CVE-2026-73493 | HIGH | Patched | 7.5 | 2026-08-12 | Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incom… |
| CVE-2026-73492 | NONE | Patched | — | 2026-08-12 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.all… |
| CVE-2026-71846 | MEDIUM | 6.5 | 2026-08-12 | A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code… | |
| CVE-2026-71473 | HIGH | 8.5 | 2026-08-12 | A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to… | |
| CVE-2026-71471 | CRITICAL | 9.0 | 2026-08-12 | A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), c… | |
| CVE-2026-71469 | HIGH | 7.5 | 2026-08-12 | A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent … | |
| CVE-2026-19003 | HIGH | 7.8 | 2026-08-12 | A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated… | |
| CVE-2026-18750 | MEDIUM | 5.3 | 2026-08-12 | vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belong… | |
| CVE-2026-18749 | CRITICAL | 9.8 | 2026-08-12 | The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been mar… | |
| CVE-2026-18744 | MEDIUM | 6.5 | 2026-08-12 | Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func only checks _is_my_case, … | |
| CVE-2026-18727 | MEDIUM | 6.5 | 2026-08-12 | A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for … |