Search
61 CVEs · published 2026-08-13 to 2026-08-13, Critical severity
CVEs (61)
Showing 1–25 of 61
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-73843 | CRITICAL | Patched | 9.6 | 2026-08-13 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs o… |
| CVE-2026-73842 | CRITICAL | Patched | 9.0 | 2026-08-13 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api… |
| CVE-2026-72851 | CRITICAL | Patched | 10.0 | 2026-08-13 | Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-contro… |
| CVE-2026-72850 | CRITICAL | Patched | 9.1 | 2026-08-13 | Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export.… |
| CVE-2026-72842 | CRITICAL | 9.9 | 2026-08-13 | luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper au… | |
| CVE-2026-72841 | CRITICAL | 9.9 | 2026-08-13 | luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary file… | |
| CVE-2026-72839 | CRITICAL | 9.8 | 2026-08-13 | filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can r… | |
| CVE-2026-72776 | CRITICAL | 9.8 | 2026-08-13 | AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by subm… | |
| CVE-2026-8715 | CRITICAL | Patched | 9.6 | 2026-08-13 | Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allo… |
| CVE-2026-19297 | CRITICAL | 9.1 | 2026-08-13 | IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts. | |
| CVE-2026-17482 | CRITICAL | Patched | 9.8 | 2026-08-13 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths. |
| CVE-2026-73656 | CRITICAL | Patched | 9.9 | 2026-08-13 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls … |
| CVE-2026-19747 | CRITICAL | 9.8 | 2026-08-13 | A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd … | |
| CVE-2026-14525 | CRITICAL | Patched | 9.4 | 2026-08-13 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 … |
| CVE-2026-73653 | CRITICAL | Patched | 9.4 | 2026-08-13 | Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screensho… |
| CVE-2026-73649 | CRITICAL | Patched | 9.8 | 2026-08-13 | Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and p… |
| CVE-2026-73644 | CRITICAL | Patched | 9.6 | 2026-08-13 | OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensio… |
| CVE-2026-73567 | CRITICAL | Patched | 9.1 | 2026-08-13 | sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.generateKeyPairHex() pa… |
| CVE-2026-67614 | CRITICAL | Patched | 9.8 | 2026-08-13 | CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid au… |
| CVE-2026-58508 | CRITICAL | 9.1 | 2026-08-13 | Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) | |
| CVE-2026-58443 | CRITICAL | 9.1 | 2026-08-13 | Public-only repository tokens can update private PR head branches | |
| CVE-2026-58433 | CRITICAL | 9.1 | 2026-08-13 | Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting | |
| CVE-2026-56750 | CRITICAL | 9.1 | 2026-08-13 | Gitea Remember-Me Token Theft Not Invalidating Attacker Session | |
| CVE-2026-56654 | CRITICAL | 9.8 | 2026-08-13 | Privilege Escalation via Access Token Scope Escalation in API | |
| CVE-2026-56443 | CRITICAL | 9.6 | 2026-08-13 | Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 |