Total
398504 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-28150 | 2026-08-20 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions. | |||||
| CVE-2025-15688 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Capella <= 2.5.5 versions. | |||||
| CVE-2026-15308 | 1 Python | 1 Python | 2026-08-20 | N/A | 7.5 HIGH |
| The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data. | |||||
| CVE-2026-20006 | 1 Cisco | 1 Secure Firewall Threat Defense | 2026-08-20 | N/A | 5.8 MEDIUM |
| A vulnerability in the TLS cryptography functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to unexpectedly restart, resulting in a denial of service (DoS) condition. This vulnerability is due to improper implementation of the TLS protocol. An attacker could exploit this vulnerability by sending a crafted TLS packet to an affected system. A successful exploit could allow the attacker to cause a device that is running Cisco Secure FTD Software to drop network traffic, resulting in a DoS condition. Note: TLS 1.3 is not affected by this vulnerability. | |||||
| CVE-2026-20007 | 1 Cisco | 1 Secure Firewall Threat Defense | 2026-08-20 | N/A | 5.8 MEDIUM |
| A vulnerability in the Snort 2 and Snort 3 deep packet inspection of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Snort rules and allow traffic onto the network that should have been dropped. This vulnerability is due to a logic error in the integration of the Snort Engine rules with Cisco Secure FTD Software that could allow different Snort rules to be hit when deep inspection of the packet is performed for the inner and outer connections. An attacker could exploit this vulnerability by sending crafted traffic to a targeted device that would hit configured Snort rules. A successful exploit could allow the attacker to send traffic to a network where it should have been denied. | |||||
| CVE-2026-20052 | 1 Cisco | 1 Secure Firewall Threat Defense | 2026-08-20 | N/A | 5.8 MEDIUM |
| A vulnerability in the memory management handling for the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart. This vulnerability is due to a logic error in memory management when a device is performing Snort 3 SSL packet inspection. An attacker could exploit this vulnerability by sending crafted SSL packets through an established connection to be parsed by the Snort 3 Detection Engine. A successful exploit could allow the attacker to cause a denial of service (DoS) condition when the Snort 3 Detection Engine unexpectedly restarts. | |||||
| CVE-2026-76785 | 2026-08-20 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Affected is the function Transaction::getAll of the file application/models/Transaction.php. Performing a manipulation of the argument orderBy/orderFormat results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | |||||
| CVE-2026-76761 | 2026-08-20 | 7.5 HIGH | 7.3 HIGH | ||
| A vulnerability was identified in chenhg5 cc-connect up to 1.4.1. This affects the function shellExecCommand of the file core/engine.go of the component Management API. Such manipulation of the argument exec leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The reported GitHub issue was closed automatically due to inactivity. | |||||
| CVE-2026-76386 | 2026-08-20 | N/A | 4.3 MEDIUM | ||
| In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could expose meeting and personal meeting ID passwords by invoking one of the create meeting, update meeting, or update user settings actions, because the affected password and pmi_password parameters are not masked and are shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameters as passwords. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises). | |||||
| CVE-2026-76166 | 2026-08-20 | N/A | 4.3 MEDIUM | ||
| A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single crafted UDP multicast datagram with a valid HTTP status line and a "Server:" header but without the "Date:", "Digest:", and "Sequence:" headers triggers a NullPointerException in verifyDigest() that is not caught by the worker thread's exception handler. This causes the advertise listener thread to terminate permanently. The failure is silent (isListening() continues to return true) and persists until the node is restarted. The crash occurs before the AdvertiseSecurityKey comparison, so deployments with a configured security key are still affected. | |||||
| CVE-2026-75963 | 2026-08-20 | N/A | 7.5 HIGH | ||
| The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The stored traversal payload is triggered passively when any visitor loads the affected single-event page, meaning post-submission execution does not require additional attacker interaction. | |||||
| CVE-2026-74021 | 2026-08-20 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions. | |||||
| CVE-2026-74020 | 2026-08-20 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Koji <= 2.2.1 versions. | |||||
| CVE-2026-74013 | 2026-08-20 | N/A | 8.5 HIGH | ||
| Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions. | |||||
| CVE-2026-73402 | 2026-08-20 | N/A | 6.5 MEDIUM | ||
| Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions. | |||||
| CVE-2026-73390 | 2026-08-20 | N/A | 9.8 CRITICAL | ||
| Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. | |||||
| CVE-2026-73389 | 2026-08-20 | N/A | 9.8 CRITICAL | ||
| Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. | |||||
| CVE-2026-73385 | 2026-08-20 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions. | |||||
| CVE-2026-73384 | 2026-08-20 | N/A | 7.5 HIGH | ||
| Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions. | |||||
| CVE-2026-73347 | 2026-08-20 | N/A | 9.8 CRITICAL | ||
| Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions. | |||||
