Search
210 CVEs · published 2026-08-13 to 2026-08-13, Medium severity
CVEs (210)
Showing 1–25 of 210
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-19756 | MEDIUM | 6.3 | 2026-08-13 | A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of the file DefGenProjectController.java of the component Code Generator. Su… | |
| CVE-2026-73840 | MEDIUM | Patched | 5.3 | 2026-08-13 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/opench… |
| CVE-2026-73657 | MEDIUM | Patched | 4.2 | 2026-08-13 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4, `POST /api/v1/runs/:runParam/replay` in apps/webapp… |
| CVE-2026-73489 | MEDIUM | Patched | 4.3 | 2026-08-13 | Russh is a Rust SSH client & server library. Prior to 0.62.4, an authenticated SSH client can cause a denial of service by sending a pty-req channel request with more than … |
| CVE-2026-73479 | MEDIUM | 5.0 | 2026-08-13 | dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attackers can craft file names containing OSC/CSI escape … | |
| CVE-2026-73428 | MEDIUM | Patched | 4.6 | 2026-08-13 | Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to stored cross-site scripting when crafted HTML is pasted… |
| CVE-2026-73304 | MEDIUM | Patched | 4.9 | 2026-08-13 | Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id returned user objects processed by packages/server/s… |
| CVE-2026-73039 | MEDIUM | 5.4 | 2026-08-13 | streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated users to read and delete other users' viewing status… | |
| CVE-2026-56860 | MEDIUM | 5.9 | 2026-08-13 | Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time … | |
| CVE-2026-56858 | MEDIUM | 6.1 | 2026-08-13 | Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS. | |
| CVE-2026-19752 | MEDIUM | 6.3 | 2026-08-13 | A vulnerability was found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. This affects the function parse-pdf of the file src/index.ts of… | |
| CVE-2026-19751 | MEDIUM | 6.3 | 2026-08-13 | A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. The affected element is the function axios.get of the file src/inde… | |
| CVE-2026-73480 | MEDIUM | 5.0 | 2026-08-13 | gdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers can craft malicious directory or file names contain… | |
| CVE-2026-18741 | MEDIUM | 4.8 | 2026-08-13 | Worksuite SaaS versions prior to 6.0.14 contains a stored cross-site scripting vulnerability in the Asset Management module that allows authenticated administrators to inje… | |
| CVE-2026-18715 | MEDIUM | 6.5 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper processing of XML external entities. | |
| CVE-2026-18671 | MEDIUM | 6.5 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to force a NetServer server thread exception, caused by an integer overflow during bounds checking in req… | |
| CVE-2026-18086 | MEDIUM | 4.5 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking. | |
| CVE-2026-18068 | MEDIUM | 4.3 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to a byte-count and element-count confusion. | |
| CVE-2026-18020 | MEDIUM | 5.3 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bounds checking. | |
| CVE-2026-17649 | MEDIUM | 5.3 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read. | |
| CVE-2026-17476 | MEDIUM | 4.8 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an improper buffer write. | |
| CVE-2026-17468 | MEDIUM | Patched | 5.3 | 2026-08-13 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to forge valid session tokens due to the use of a hardcoded cryptographic key. |
| CVE-2026-17438 | MEDIUM | 4.4 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify data due to improper privilege management. | |
| CVE-2026-17226 | MEDIUM | 5.4 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read. | |
| CVE-2026-17216 | MEDIUM | 5.3 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an integer error when processing DRDA large-object headers. |