Total
398379 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-59639 | 1 Bouncycastle | 3 Bc-java, Bcpkix-fips, Bouncy Castle For Java Lts | 2026-08-28 | N/A | 7.5 HIGH |
| In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series). | |||||
| CVE-2026-16809 | 2026-08-28 | N/A | N/A | ||
| LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own survey can store malicious JavaScript in a quota message. This issue affects LimeSurvey: 7.0.5. | |||||
| CVE-2026-63360 | 2026-08-28 | N/A | N/A | ||
| LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied into the response and inserted into a hidden input attribute without HTML attribute encoding. This issue affects LimeSurvey: 7.0.5. | |||||
| CVE-2026-15973 | 2026-08-28 | N/A | N/A | ||
| LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the Survey Menu Entries administration page. An authenticated user with the global settings:read permission can create a survey menu entry containing attacker-controlled data. The value is stored in the surveymenu_entries.data field and later inserted into a single-quoted HTML title attribute without context-appropriate encoding. This issue affects LimeSurvey: 7.0.5. | |||||
| CVE-2026-19755 | 2026-08-28 | N/A | N/A | ||
| NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled command and NSBundlePath values.This issue affects NoSleep: 1.5.1. | |||||
| CVE-2026-18430 | 2026-08-28 | N/A | N/A | ||
| HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notification flow. A Space administrator can delete another user's comment, choose to notify the original author, and place HTML/JavaScript in the deletion reason. | |||||
| CVE-2026-19198 | 2026-08-28 | N/A | N/A | ||
| Akaunting 3.1.21 contains an authenticated improper authorization vulnerability in the common BulkActions dispatcher.This issue affects Akaunting: 3.1.21. | |||||
| CVE-2026-65930 | 2026-08-28 | N/A | N/A | ||
| LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.This issue affects LimeSurvey: 7.0.5. | |||||
| CVE-2026-13229 | 2026-08-28 | N/A | N/A | ||
| Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint. | |||||
| CVE-2026-13227 | 2026-08-28 | N/A | N/A | ||
| An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities. This issue affects ERPNext: before 15.115.0, before 16.26.0. | |||||
| CVE-2026-18526 | 2026-08-28 | N/A | N/A | ||
| HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflow. | |||||
| CVE-2026-18403 | 2026-08-28 | N/A | N/A | ||
| LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central participant list. | |||||
| CVE-2026-10716 | 2026-08-28 | N/A | N/A | ||
| Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with geometry but contains attacker-controlled SQL syntax after the geometry subtype.This issue affects Directus: before 12.1.0. | |||||
| CVE-2026-18756 | 2026-08-28 | N/A | N/A | ||
| HumHub Community Edition 1.18.4 contains a reflected cross-site scripting vulnerability in the Space membership-request workflow. An attacker can place attacker-controlled button configuration in the options query-string parameter of space/membership/request-membership-form, lure an authenticated non-member into submitting the legitimate membership request form, and cause the server to return JavaScript containing attacker-controlled code. | |||||
| CVE-2026-63361 | 2026-08-28 | N/A | N/A | ||
| LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text and name query parameters are passed through a blacklist sanitizer and then rendered without context-appropriate output encoding. | |||||
| CVE-2026-16638 | 2026-08-28 | N/A | 6.1 MEDIUM | ||
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from 0.0.0 to 1.0.8. | |||||
| CVE-2026-16641 | 2026-08-28 | N/A | 9.8 CRITICAL | ||
| Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*. | |||||
| CVE-2026-16643 | 2026-08-28 | N/A | 5.7 MEDIUM | ||
| Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*. | |||||
| CVE-2026-15088 | 2026-08-28 | N/A | 5.7 MEDIUM | ||
| Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*. | |||||
| CVE-2026-18985 | 2026-08-28 | N/A | 8.1 HIGH | ||
| Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1. | |||||
