Total
398081 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-19755 | 2026-08-28 | N/A | N/A | ||
| NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled command and NSBundlePath values.This issue affects NoSleep: 1.5.1. | |||||
| CVE-2026-18430 | 2026-08-28 | N/A | N/A | ||
| HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notification flow. A Space administrator can delete another user's comment, choose to notify the original author, and place HTML/JavaScript in the deletion reason. | |||||
| CVE-2026-19198 | 2026-08-28 | N/A | N/A | ||
| Akaunting 3.1.21 contains an authenticated improper authorization vulnerability in the common BulkActions dispatcher.This issue affects Akaunting: 3.1.21. | |||||
| CVE-2026-65930 | 2026-08-28 | N/A | N/A | ||
| LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.This issue affects LimeSurvey: 7.0.5. | |||||
| CVE-2026-13229 | 2026-08-28 | N/A | N/A | ||
| Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint. | |||||
| CVE-2026-13227 | 2026-08-28 | N/A | N/A | ||
| An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities. This issue affects ERPNext: before 15.115.0, before 16.26.0. | |||||
| CVE-2026-18526 | 2026-08-28 | N/A | N/A | ||
| HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflow. | |||||
| CVE-2026-18403 | 2026-08-28 | N/A | N/A | ||
| LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central participant list. | |||||
| CVE-2026-10716 | 2026-08-28 | N/A | N/A | ||
| Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with geometry but contains attacker-controlled SQL syntax after the geometry subtype.This issue affects Directus: before 12.1.0. | |||||
| CVE-2026-18756 | 2026-08-28 | N/A | N/A | ||
| HumHub Community Edition 1.18.4 contains a reflected cross-site scripting vulnerability in the Space membership-request workflow. An attacker can place attacker-controlled button configuration in the options query-string parameter of space/membership/request-membership-form, lure an authenticated non-member into submitting the legitimate membership request form, and cause the server to return JavaScript containing attacker-controlled code. | |||||
| CVE-2026-63361 | 2026-08-28 | N/A | N/A | ||
| LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text and name query parameters are passed through a blacklist sanitizer and then rendered without context-appropriate output encoding. | |||||
| CVE-2026-16638 | 2026-08-28 | N/A | 6.1 MEDIUM | ||
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from 0.0.0 to 1.0.8. | |||||
| CVE-2026-16641 | 2026-08-28 | N/A | 9.8 CRITICAL | ||
| Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*. | |||||
| CVE-2026-16643 | 2026-08-28 | N/A | 5.7 MEDIUM | ||
| Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*. | |||||
| CVE-2026-15088 | 2026-08-28 | N/A | 5.7 MEDIUM | ||
| Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*. | |||||
| CVE-2026-18985 | 2026-08-28 | N/A | 8.1 HIGH | ||
| Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1. | |||||
| CVE-2026-15916 | 2026-08-28 | N/A | 4.2 MEDIUM | ||
| Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*. | |||||
| CVE-2026-55805 | 2026-08-28 | N/A | 5.4 MEDIUM | ||
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*. | |||||
| CVE-2026-16639 | 2026-08-28 | N/A | 9.8 CRITICAL | ||
| Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0. | |||||
| CVE-2026-16644 | 2026-08-28 | N/A | 9.1 CRITICAL | ||
| Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0. | |||||
