Search
259 CVEs · published 2026-08-13 to 2026-08-13, High severity
CVEs (259)
Showing 1–25 of 259
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-19753 | HIGH | 7.3 | 2026-08-13 | A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/server.py of the compon… | |
| CVE-2026-73841 | HIGH | Patched | 8.8 | 2026-08-13 | OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-a… |
| CVE-2026-73667 | HIGH | Patched | 8.8 | 2026-08-13 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-st… |
| CVE-2026-73666 | HIGH | Patched | 8.2 | 2026-08-13 | OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPo… |
| CVE-2026-73659 | HIGH | Patched | 8.1 | 2026-08-13 | Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.5.0, the packet presign routes in apps/webapp/app/routes/api.v1.packets.… |
| CVE-2026-73658 | HIGH | Patched | 8.2 | 2026-08-13 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.pres… |
| CVE-2026-73408 | HIGH | Patched | 7.6 | 2026-08-13 | Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multipleStatements and inserted an unescaped tableName int… |
| CVE-2026-73305 | HIGH | Patched | 8.8 | 2026-08-13 | Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.a… |
| CVE-2026-72857 | HIGH | Patched | 7.7 | 2026-08-13 | Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase pr… |
| CVE-2026-72856 | HIGH | Patched | 8.1 | 2026-08-13 | Budibase versions before 3.40.0 contain an authorization/authentication bypass in the PUT /api/global/users/tenant/owner (changeTenantOwnerEmail) endpoint. On self-hosted i… |
| CVE-2026-72855 | HIGH | Patched | 8.5 | 2026-08-13 | Budibase before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import and REST query execution that allow authenticated builder-level users to… |
| CVE-2026-72853 | HIGH | Patched | 7.6 | 2026-08-13 | Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table names in identifiers. At… |
| CVE-2026-72849 | HIGH | Patched | 7.7 | 2026-08-13 | Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a vi… |
| CVE-2026-72840 | HIGH | 8.8 | 2026-08-13 | OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configur… | |
| CVE-2026-56865 | HIGH | 8.4 | 2026-08-13 | A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled mo… | |
| CVE-2026-56864 | HIGH | 7.5 | 2026-08-13 | A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to … | |
| CVE-2026-56862 | HIGH | 7.5 | 2026-08-13 | Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious clien… | |
| CVE-2026-56859 | HIGH | 7.5 | 2026-08-13 | Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion. | |
| CVE-2026-56853 | HIGH | 7.5 | 2026-08-13 | When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout… | |
| CVE-2026-33818 | HIGH | 7.5 | 2026-08-13 | Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. | |
| CVE-2026-19750 | HIGH | 8.1 | 2026-08-13 | A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue is some unknown functionality of the component SSH. Executing a manipula… | |
| CVE-2026-19483 | HIGH | Patched | 7.1 | 2026-08-13 | IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Storage Scale Management GUI The admin password is logge… |
| CVE-2026-18511 | HIGH | 7.3 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Native IBM i JSSE provider, caused by improper boun… | |
| CVE-2026-18509 | HIGH | 8.2 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator for i debugger. This could allow the attacker to acce… | |
| CVE-2026-18249 | HIGH | 8.4 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from Java-controlled addresses. |