CVE Feed

    Dashboard / CVE

    4.4
    Medium

    CVE-2026-18822

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to uncontrolled resource consumption when parsing directory records.

    Published: 20 Aug 2026
    7.9
    High

    CVE-2026-18716

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.

    Published: 20 Aug 2026
    8.2
    High

    CVE-2026-18670

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service and potentially disclose sensitive information due to an integer underflow.

    Published: 20 Aug 2026
    8.8
    High

    CVE-2026-17436

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.

    Published: 20 Aug 2026
    7.5
    High

    CVE-2026-17425

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack buffer overflow.

    Published: 20 Aug 2026
    4.8
    Medium

    CVE-2026-17424

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restrictions due to improper limitation of a pathname to a restricted directory.

    Published: 20 Aug 2026
    7.7
    High

    CVE-2026-17423

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds read.

    Published: 20 Aug 2026
    9.3
    Critical

    CVE-2026-17422

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow.

    Published: 20 Aug 2026
    7.7
    High

    CVE-2026-72848

    Last Modified: 21 Aug 2026

    SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over nested sitemap elements passes the child loc straight to self.scrape_all([loc.text], "xml"), which reaches WebBaseLoader.scrape_all and an aiohttp GET, with no domain comparison and no check for private, loopback or link-local destinations. An attacker who controls or influences an ingested sitemap can therefore point a nested sitemap entry at an internal address and make the server fetch it even when the deploying application set restrict_to_same_domain to True specifically to confine outbound requests. The fetched content is parsed and surfaces in the returned Documents, so internal responses are disclosed to the caller rather than merely requested.

    Published: 20 Aug 2026
    5.3
    Medium

    CVE-2026-72846

    Last Modified: 21 Aug 2026

    Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/clients/MicrosoftTeams/MicrosoftTeamsClient.ts. In affected versions both call fetch on the stored URL directly. The validatePublicHttpUrl helper in packages/backend/src/utils/ssrfProtection.ts, used for MCP server URLs, is not applied on either path, and the webhook fields carry no server-side URL constraint. A user able to create or trigger a scheduled delivery can therefore direct the server to issue POST requests to private, loopback and link-local addresses, including cloud metadata endpoints, and can distinguish reachable internal services from unreachable ones through the resulting errors. The upstream response is never returned to the requester; on a failure status its body is written to the server log instead. Version 1.146.4 routes both clients through postSchedulerWebhook from packages/backend/src/utils/schedulerWebhookValidation rather than calling fetch directly.

    Published: 20 Aug 2026
    9.3
    Critical

    CVE-2026-72843

    Last Modified: 21 Aug 2026

    The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the caller, and no customer-session middleware guards the route; the only middleware in the chain parses the JSON body. The handler in updateCustomer.js then loads the customer by the uuid taken from the URL path and writes the supplied fields back to that record, hashing a password if one is provided, without verifying that the caller owns the record. An unauthenticated request carrying a known customer uuid can therefore overwrite that customer's email address and password and read back the updated record from the 200 response, taking over the account and locking out its owner. Customer uuids are exposed through order confirmation email links and administrative URLs. Version 2.2.1 changes the route to "access": "private".

    Published: 20 Aug 2026
    8.7
    High

    CVE-2026-72818

    Last Modified: 21 Aug 2026

    The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisting of many alternating label separators can be partitioned in exponentially many ways, and because the branch also requires a trailing top-level domain that such input never supplies, the engine explores those partitions before failing at each offset. A few kilobytes of input therefore consumes seconds to minutes of single-threaded CPU, and the HANG_RE substitution performed before matching does not collapse the pattern. TweetTokenizer is intended for tokenizing untrusted social-media text, so any service that applies it, or the module-level casual_tokenize, to submitted text can be stalled per request without authentication. Version 3.10.1 bounds the label repetition.

    Published: 20 Aug 2026
    6.5
    Medium

    CVE-2026-17195

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of-bounds write.

    Published: 20 Aug 2026
    7.8
    High

    CVE-2026-17171

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary files due to improper resolution of symbolic links.

    Published: 20 Aug 2026
    7.5
    High

    CVE-2026-17170

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper validation of an allocation size.

    Published: 20 Aug 2026
    8.5
    High

    CVE-2026-17168

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow.

    Published: 20 Aug 2026
    7.5
    High

    CVE-2026-17165

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL pointer dereference.

    Published: 20 Aug 2026
    7.5
    High

    CVE-2026-17163

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper validation of an array size field.

    Published: 20 Aug 2026
    9.8
    Critical

    CVE-2026-17160

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during size computation.

    Published: 20 Aug 2026
    7.5
    High

    CVE-2026-17159

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer overflow.

    Published: 20 Aug 2026
    9.8
    Critical

    CVE-2026-17157

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

    Published: 20 Aug 2026
    9.8
    Critical

    CVE-2026-17152

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

    Published: 20 Aug 2026
    9.3
    Critical

    CVE-2026-77644

    Last Modified: 26 Aug 2026

    A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.

    Published: 20 Aug 2026
    9.8
    Critical

    CVE-2026-17145

    Last Modified: 27 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper privilege management.

    Published: 20 Aug 2026
    9.8
    Critical

    CVE-2026-17142

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper authentication.

    Published: 20 Aug 2026
    9.8
    Critical

    CVE-2026-17141

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

    Published: 20 Aug 2026
    8.1
    High

    CVE-2026-17138

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

    Published: 20 Aug 2026
    5.9
    Medium

    CVE-2026-49244

    Last Modified: 21 Aug 2026

    SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP download endpoint for a browsable share validates client-supplied files entries with a raw byte-prefix comparison rather than a directory-boundary-aware check. An unauthenticated requester who can reach a public share can select a canonical path outside the shared directory when the target path begins with the shared directory's name, such as a sibling path that shares the same prefix. The endpoint then includes the out-of-scope file in the generated download, disclosing its contents. This issue is fixed in version 2.7.3.

    Published: 20 Aug 2026
    9.8
    Critical

    CVE-2026-17136

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format string vulnerability.

    Published: 20 Aug 2026
    7.8
    High

    CVE-2026-17124

    Last Modified: 27 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an out-of-bounds read.

    Published: 20 Aug 2026
    9.8
    Critical

    CVE-2026-17122

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

    Published: 20 Aug 2026
    3.7
    Low

    CVE-2026-49245

    Last Modified: 21 Aug 2026

    SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses Content-Disposition: attachment, allowing an attacker-controlled HTML file stored in a share or home directory to be served as text/html in the SFTPGo web origin. An attacker who can place the file can send a crafted link to a victim, and opening that link executes the stored content in the victim's browser context. Exploitation requires social engineering and suitable share or shared-folder access, while HttpOnly session cookies limit direct cookie theft. This issue is fixed in version 2.7.3.

    Published: 20 Aug 2026
    7.5
    High

    CVE-2026-17121

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.

    Published: 20 Aug 2026
    5.3
    Medium

    CVE-2026-17120

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a buffer overflow.

    Published: 20 Aug 2026
    9.8
    Critical

    CVE-2026-17118

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after-free vulnerability.

    Published: 20 Aug 2026
    8.1
    High

    CVE-2026-17060

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to a kernel heap over-read.

    Published: 20 Aug 2026
    4.3
    Medium

    CVE-2026-62945

    Last Modified: 21 Aug 2026

    TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions accept attacker-controlled reservation_id, place_id, and assignment_id values without using findForeignLinkTarget() to verify that the referenced object belongs to the file's trip. An authenticated user with file-edit permission on any accessible trip can submit a foreign reservation identifier through POST /api/trips/:tripId/files/:id/link, POST /api/trips/:tripId/files, or PUT /api/trips/:tripId/files/:id. Subsequent reads through FILE_SELECT or getFileLinks() join the foreign reservation and return reservation_title, disclosing reservation existence and titles across private trip boundaries. This issue is fixed in version 3.1.3.

    Published: 20 Aug 2026
    9.8
    Critical

    CVE-2026-17040

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

    Published: 20 Aug 2026
    7.7
    High

    CVE-2026-17024

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper certificate validation.

    Published: 20 Aug 2026
    6.5
    Medium

    CVE-2026-54509

    Last Modified: 21 Aug 2026

    TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src/routes/journey.ts returns the result of getJourneyShareLink() from server/src/services/journeyShareService.ts without checking whether the authenticated requester can access the journey. Any ordinary authenticated user can enumerate sequential journey IDs and retrieve tokens from journey_share_tokens for another user's journey. The token grants unauthenticated access through GET /api/public/journey/:token to the shared journey's entries, captions, locations, moods, gallery photos, photo paths, and asset identifiers. This issue is fixed in version 3.1.0.

    Published: 20 Aug 2026
    4.7
    Medium

    CVE-2026-17009

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to a NULL pointer dereference.

    Published: 20 Aug 2026
    6.7
    Medium

    CVE-2026-17007

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.

    Published: 20 Aug 2026
    8.3
    High

    CVE-2026-17006

    Last Modified: 27 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.

    Published: 20 Aug 2026
    7.7
    High

    CVE-2026-17003

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confidentiality and integrity of the system due to an out-of-bounds write.

    Published: 20 Aug 2026
    8.1
    High

    CVE-2026-17000

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper authentication.

    Published: 20 Aug 2026
    7.8
    High

    CVE-2026-16997

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper privilege management.

    Published: 20 Aug 2026
    8.8
    High

    CVE-2026-16996

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an integer underflow.

    Published: 20 Aug 2026
    7.8
    High

    CVE-2026-16991

    Last Modified: 27 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper handling of symbolic links.

    Published: 20 Aug 2026
    7.7
    High

    CVE-2026-69855

    Last Modified: 8 Sept 2026

    Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.

    Published: 20 Aug 2026
    8.5
    High

    CVE-2026-69543

    Last Modified: 26 Aug 2026

    Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.

    Published: 20 Aug 2026