Total
1153 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-66682 | 2026-08-20 | N/A | 9.8 CRITICAL | ||
| Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. | |||||
| CVE-2026-73390 | 2026-08-20 | N/A | 9.8 CRITICAL | ||
| Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. | |||||
| CVE-2026-73347 | 2026-08-20 | N/A | 9.8 CRITICAL | ||
| Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions. | |||||
| CVE-2025-15689 | 2026-08-20 | N/A | 9.8 CRITICAL | ||
| Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions. | |||||
| CVE-2026-73350 | 2026-08-20 | N/A | 8.2 HIGH | ||
| Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions. | |||||
| CVE-2026-19928 | 2026-08-20 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Role Interceptor. Executing a manipulation can lead to improper privilege management. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.9.8-hotfix1 and 0.9.8 mitigates this issue. This patch is called 788cace0af816aa972a713a4631c57f16f895e6b. Upgrading the affected component is recommended. | |||||
| CVE-2024-14045 | 2026-08-20 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Product Supplier Edit Controller. Executing a manipulation can lead to improper authorization. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.9.3 is able to resolve this issue. This patch is called f767ac1a5987d4865d9f158c6a967680f8e45468. It is suggested to upgrade the affected component. | |||||
| CVE-2026-68568 | 2026-08-20 | N/A | 6.3 MEDIUM | ||
| Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions. | |||||
| CVE-2026-19893 | 2026-08-20 | 2.1 LOW | 3.1 LOW | ||
| A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Such manipulation leads to incorrect default permissions. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. | |||||
| CVE-2026-19918 | 2026-08-20 | 5.8 MEDIUM | 6.3 MEDIUM | ||
| A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Management Interface. The manipulation leads to improper access controls. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-19986 | 2026-08-20 | 6.4 MEDIUM | 5.4 MEDIUM | ||
| A weakness has been identified in Adblock for Youtube Extension up to 7.2.1 on Chrome. The impacted element is the function updateDynamicRules of the file contentscript.js of the component Event Listener. This manipulation of the argument yt-anti-adblock-detected causes improper authorization. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-19996 | 2026-08-20 | 4.0 MEDIUM | 4.3 MEDIUM | ||
| A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior Data Endpoint. Such manipulation of the argument ID leads to improper privilege management. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases." | |||||
| CVE-2025-9486 | 1 Gitlab | 1 Gitlab | 2026-08-19 | N/A | 3.3 LOW |
| GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a custom role, due to incorrect privilege assignment that did not account for membership state. | |||||
| CVE-2026-26053 | 1 Gallagher | 1 Command Centre | 2026-08-18 | N/A | 5.3 MEDIUM |
| An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to perform some operations that they would not normally be authorized to perform. Version of Command Centre affected: 9.50 prior to vEL9.50.1587(MR1), 9.40 prior to vEL9.40.3130(MR3), 9.30 prior to vEL9.30.3983(MR5), 9.20 prior to vEL9.20.4349(MR7), all versions of 9.10. | |||||
| CVE-2026-19835 | 2026-08-14 | 4.7 MEDIUM | 3.8 LOW | ||
| A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases." | |||||
| CVE-2026-66661 | 2026-08-14 | N/A | 7.7 HIGH | ||
| Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions. | |||||
| CVE-2026-19841 | 2026-08-14 | 2.1 LOW | 3.1 LOW | ||
| A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes incorrect default permissions. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitability is considered difficult. This vulnerability only affects products that are no longer supported by the maintainer. | |||||
| CVE-2026-28161 | 2026-08-14 | N/A | 8.8 HIGH | ||
| Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions. | |||||
| CVE-2026-61979 | 2026-08-14 | N/A | 8.1 HIGH | ||
| Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions. | |||||
| CVE-2026-66424 | 2026-08-14 | N/A | 9.8 CRITICAL | ||
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. | |||||
