Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

210 CVEs · published 2026-08-13 to 2026-08-13, Medium severity

CVEs (210)

Showing 1–25 of 210

CVE ID Severity Patch CVSS Published Description
CVE-2026-19756 MEDIUM 6.3 2026-08-13 A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of the file DefGenProjectController.java of the component Code Generator. Su…
CVE-2026-73840 MEDIUM Patched 5.3 2026-08-13 OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/opench…
CVE-2026-73657 MEDIUM Patched 4.2 2026-08-13 Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4, `POST /api/v1/runs/:runParam/replay` in apps/webapp…
CVE-2026-73489 MEDIUM Patched 4.3 2026-08-13 Russh is a Rust SSH client & server library. Prior to 0.62.4, an authenticated SSH client can cause a denial of service by sending a pty-req channel request with more than …
CVE-2026-73479 MEDIUM 5.0 2026-08-13 dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attackers can craft file names containing OSC/CSI escape …
CVE-2026-73428 MEDIUM Patched 4.6 2026-08-13 Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to stored cross-site scripting when crafted HTML is pasted…
CVE-2026-73304 MEDIUM Patched 4.9 2026-08-13 Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id returned user objects processed by packages/server/s…
CVE-2026-73039 MEDIUM 5.4 2026-08-13 streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated users to read and delete other users' viewing status…
CVE-2026-56860 MEDIUM 5.9 2026-08-13 Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time …
CVE-2026-56858 MEDIUM 6.1 2026-08-13 Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.
CVE-2026-19752 MEDIUM 6.3 2026-08-13 A vulnerability was found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. This affects the function parse-pdf of the file src/index.ts of…
CVE-2026-19751 MEDIUM 6.3 2026-08-13 A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. The affected element is the function axios.get of the file src/inde…
CVE-2026-73480 MEDIUM 5.0 2026-08-13 gdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers can craft malicious directory or file names contain…
CVE-2026-18741 MEDIUM 4.8 2026-08-13 Worksuite SaaS versions prior to 6.0.14 contains a stored cross-site scripting vulnerability in the Asset Management module that allows authenticated administrators to inje…
CVE-2026-18715 MEDIUM 6.5 2026-08-13 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper processing of XML external entities.
CVE-2026-18671 MEDIUM 6.5 2026-08-13 IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to force a NetServer server thread exception, caused by an integer overflow during bounds checking in req…
CVE-2026-18086 MEDIUM 4.5 2026-08-13 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking.
CVE-2026-18068 MEDIUM 4.3 2026-08-13 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to a byte-count and element-count confusion.
CVE-2026-18020 MEDIUM 5.3 2026-08-13 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bounds checking.
CVE-2026-17649 MEDIUM 5.3 2026-08-13 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
CVE-2026-17476 MEDIUM 4.8 2026-08-13 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an improper buffer write.
CVE-2026-17468 MEDIUM Patched 5.3 2026-08-13 IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to forge valid session tokens due to the use of a hardcoded cryptographic key.
CVE-2026-17438 MEDIUM 4.4 2026-08-13 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify data due to improper privilege management.
CVE-2026-17226 MEDIUM 5.4 2026-08-13 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.
CVE-2026-17216 MEDIUM 5.3 2026-08-13 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an integer error when processing DRDA large-object headers.