CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2026-19966

    Last Modified: 17 Aug 2026

    A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affects some unknown processing of the file /clients/save_contact of the component Contact Information Update. Such manipulation of the argument contact_id leads to authorization bypass. The attack can be launched remotely. The exploit is publicly available and might be used.

    Published: 17 Aug 2026
    2.9
    Low

    CVE-2026-19965

    Last Modified: 19 Aug 2026

    A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the function requestPasswordResetToken of the file automad/src/server/Controllers/API/UserController.php of the component Password Reset Endpoint. This manipulation of the argument name-or-email causes observable response discrepancy. The attack can be initiated remotely. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.0.0-beta.33 is able to resolve this issue. Patch name: eac0b05dafdb0ddf8b9139dad8929aaba86568ca. You should upgrade the affected component.

    Published: 17 Aug 2026
    9.1
    Critical

    CVE-2026-18963

    Last Modified: 8 Sept 2026

    A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-67919

    Last Modified: 21 Aug 2026

    An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components

    Published: 17 Aug 2026
    9.1
    Critical

    CVE-2026-51346

    Last Modified: 21 Aug 2026

    SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensitive information via the store() functions.

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-68004

    Last Modified: 21 Aug 2026

    An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), SrsSecurity::check(), trunk/src/app/srs_app_security.cpp, and SRS RTMP listener components

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-67960

    Last Modified: 18 Aug 2026

    An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components

    Published: 17 Aug 2026
    7.8
    High

    CVE-2026-50773

    Last Modified: 21 Aug 2026

    An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 allows a remote attacker to execute arbtirary code via a crafted .dll file.

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-50770

    Last Modified: 21 Aug 2026

    An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted request.

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-39255

    Last Modified: 18 Aug 2026

    Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, dup_wcs components

    Published: 17 Aug 2026
    6.3
    Medium

    CVE-2026-75032

    Last Modified: 18 Aug 2026

    A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability, affecting the parse_media_element() and parse_media_folder() functions, can lead to a crash of the bluetoothd daemon, resulting in a Denial of Service (DoS). It could also potentially expose sensitive heap memory contents. Exploitation requires user interaction to pair with the malicious device.

    Published: 17 Aug 2026
    6.1
    Medium

    CVE-2026-67925

    Last Modified: 18 Aug 2026

    Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the endpoint /airag/chat/upload

    Published: 17 Aug 2026
    7.8
    High

    CVE-2026-67961

    Last Modified: 18 Aug 2026

    An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke script execution.

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-38165

    Last Modified: 18 Aug 2026

    A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-67966

    Last Modified: 18 Aug 2026

    Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell access.

    Published: 17 Aug 2026
    7.5
    High

    CVE-2026-67918

    Last Modified: 18 Aug 2026

    Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in api/hermes/download endpoint

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-67854

    Last Modified: 18 Aug 2026

    SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code

    Published: 17 Aug 2026
    9.1
    Critical

    CVE-2026-51977

    Last Modified: 18 Aug 2026

    An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the RSA private key component

    Published: 17 Aug 2026
    6.1
    Medium

    CVE-2026-50771

    Last Modified: 18 Aug 2026

    Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbtirary code via the Email Notification, Create Evaluation Sets and HTML Editor functions.

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-42163

    Last Modified: 18 Aug 2026

    Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI 1.1 and LTI 1.3 Advantage.

    Published: 17 Aug 2026
    9.1
    Critical

    CVE-2026-42162

    Last Modified: 18 Aug 2026

    Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact in a page is manipulated.

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-67965

    Last Modified: 21 Aug 2026

    An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login function

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-67967

    Last Modified: 18 Aug 2026

    Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-44867 and CVE-2026-36819

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-67926

    Last Modified: 21 Aug 2026

    An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-67868

    Last Modified: 18 Aug 2026

    A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This allows a remote attacker to execute arbitrary code.

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-67678

    Last Modified: 18 Aug 2026

    File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-42164

    Last Modified: 18 Aug 2026

    Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to recall the backed-up content from another Text section.

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-39254

    Last Modified: 18 Aug 2026

    Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, CxAudioHidDevice::DeviceGetDescriptionString components

    Published: 17 Aug 2026
    7.5
    High

    CVE-2026-68005

    Last Modified: 18 Aug 2026

    An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in the handle_request() function

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-50775

    Last Modified: 21 Aug 2026

    A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content or any errors directly.

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-50774

    Last Modified: 21 Aug 2026

    An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role.

    Published: 17 Aug 2026
    7.5
    High

    CVE-2026-50776

    Last Modified: 18 Aug 2026

    Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote attacker to obtain sensitive information and execute arbitrary code.

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-50772

    Last Modified: 21 Aug 2026

    An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function.

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-50769

    Last Modified: 21 Aug 2026

    The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conflict endpoint index.php?module=Appointments&action=CheckConflictOfDates&ajaxSkipHeader=true which is used to check any conflicts for user calendar is vulnerable to SQL injection allowing an attacker to execute arbitrary code.

    Published: 17 Aug 2026
    8.8
    High

    CVE-2026-50768

    Last Modified: 28 Aug 2026

    File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function.

    Published: 17 Aug 2026
    7.1
    High

    CVE-2026-74579

    Last Modified: 25 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: fix mask build for partial field offload nft_payload_offload_mask() builds the offload match mask for a payload expression that covers only part of a header field. For a partial IPv6 address match (field_len = 16, priv_len = 1) that shift is 1 << 120, which is undefined on the 32-bit int operand. It also trims only one word, so the remaining words stay 0xffffffff (and when priv_len is a multiple of 4 the trim is skipped entirely), leaving the mask covering more bytes than the rule matches. UBSAN: shift-out-of-bounds in net/netfilter/nft_payload.c:278:20 shift exponent 120 is too large for 32-bit type 'int' ... The match is byte-granular and struct nft_data is zero-initialised, so the correct mask is simply the first priv_len bytes set to 0xff. Set those bytes directly and drop the word/shift trimming; this removes the undefined shift and no longer over-masks the trailing bytes.

    Published: 17 Aug 2026
    9.8
    Critical

    CVE-2026-67917

    Last Modified: 18 Aug 2026

    zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` command executes the `db.sql` file extracted from a backup archive without any content validation or sanitization. This allows a remote attacker to escalate privileges

    Published: 17 Aug 2026
    2
    Low

    CVE-2026-19964

    Last Modified: 18 Aug 2026

    A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run of the file jij_mcp/python_repr.py of the component jm_check. The manipulation of the argument code results in code injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 16 Aug 2026
    2.1
    Low

    CVE-2026-19963

    Last Modified: 17 Aug 2026

    A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by this issue is the function stainfo of the file /goform/stainfo. The manipulation of the argument interface leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Aug 2026
    2.1
    Low

    CVE-2026-19962

    Last Modified: 18 Aug 2026

    A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setWAN of the file /goform/setWAN. Executing a manipulation of the argument pppUserName/pptpUserName/L2TPUserName can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Aug 2026
    8.6
    High

    CVE-2026-19961

    Last Modified: 17 Aug 2026

    A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Aug 2026
    2.1
    Low

    CVE-2026-19960

    Last Modified: 19 Aug 2026

    A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function formWlbasic of the file /goform/formWlbasic. Such manipulation of the argument rootAPmac leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Aug 2026
    8.6
    High

    CVE-2026-19959

    Last Modified: 16 Aug 2026

    A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Aug 2026
    2.1
    Low

    CVE-2026-19958

    Last Modified: 17 Aug 2026

    A security flaw has been discovered in iatsiuk pptr-mcp up to 0.2.7. The impacted element is the function executeCode of the file src/vm-executor.ts of the component execute Tool. The manipulation results in code injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 16 Aug 2026
    2.1
    Low

    CVE-2026-19957

    Last Modified: 18 Aug 2026

    A vulnerability was identified in graphlit graphlit-mcp-server 1.0.1. This affects the function fetch of the file src/tools.ts of the component ssrf-test Endpoint. Such manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 16 Aug 2026
    5.3
    Medium

    CVE-2026-19956

    Last Modified: 17 Aug 2026

    A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is the function fetch_pagination_url of the file server.py. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The name of the patch is 4e53875aa22e8991c2fa4a7660d86e1caba66659. Applying a patch is advised to resolve this issue.

    Published: 16 Aug 2026
    2
    Low

    CVE-2026-19955

    Last Modified: 20 Aug 2026

    A vulnerability was detected in TrailDB 0.6. Impacted is the function tdb_open of the file /src/tdb.c of the component TOC Validation. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 16 Aug 2026
    6.5
    Medium

    CVE-2026-72888

    Last Modified: 17 Aug 2026

    Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require. smart_require stores results in a process-global hash with no bound and no eviction, and keeps an entry for every class name it is asked about, including names that failed to load, because the return value of the failed eval is stored before the error is checked. The key comes off the wire on the server side: _signature_method_class builds the class name from the signature_method parameter of the incoming message, and verify resolves it before any signature is checked. A remote client chooses both how many entries are created and how long each key is. In a persistent server the hash grows for the life of the worker process until it exhausts memory. Header size limits bound the key length on the Authorization header path, but not on a POST body.

    Published: 16 Aug 2026
    9.8
    Critical

    CVE-2026-72887

    Last Modified: 17 Aug 2026

    Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token. Passing a callback to the constructor selects OAuth 1.0a. get_request_token then revokes that choice when the request token response omits oauth_callback_confirmed, with no exception, no warning and no option to require 1.0a. The access token request is built from the OAuth 1.0 message class, which has no verifier parameter, so oauth_verifier is dropped from the request even when get_access_token was passed one. oauth_verifier is the binding that OAuth 1.0a added between the authorization step and the token exchange. An application that asked for 1.0a and gets 1.0 is open to OAuth 1.0 session fixation, where an attacker obtains a request token, has the victim authorize it, and then completes the exchange themselves, linking the victim's provider account to a session the attacker controls. No attacker action sets up the downgrade: a provider that does not confirm the callback is enough.

    Published: 16 Aug 2026
    9.8
    Critical

    CVE-2026-19349

    Last Modified: 17 Aug 2026

    Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends. Before redirecting to the identity provider, extractFormInfo() creates the state session with the positional call `getApacheSession( undef, 1, 0, 'GitHubState' )`. getApacheSession() takes a session id followed by a named argument hash, so the trailing arguments become that hash, `kind` defaults to SSO, and the state is written to the global session storage as a regular SSO session. Its identifier is handed to the unauthenticated visitor as the state parameter of the redirection URL. Any visitor who reaches the GitHub or LinkedIn endpoint can replay that identifier as a session cookie and obtain a valid SSO session without authenticating. The session holds neither _user nor authenticationLevel, which the shipped bootstrap configuration accepts because it grants virtual hosts a "default => accept" access rule; deployments whose rules test the user or require an authentication level are less exposed. Only configurations with the GitHub or LinkedIn authentication module enabled are affected.

    Published: 16 Aug 2026