Total
398517 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-75935 | 2026-08-20 | N/A | 7.5 HIGH | ||
| Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted Ion binary document containing a declared-length field that causes excessive heap preallocation. To remediate this issue, users should upgrade to version 1.12.0. | |||||
| CVE-2026-20232 | 2026-08-20 | N/A | 5.4 MEDIUM | ||
| A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of another user. To exploit this vulnerability, the attacker must have valid user credentials on the affected system. | |||||
| CVE-2026-20327 | 2026-08-20 | N/A | 6.5 MEDIUM | ||
| A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to read the contents of the internal database of an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device. | |||||
| CVE-2026-20314 | 2026-08-20 | N/A | 5.0 MEDIUM | ||
| A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device. | |||||
| CVE-2026-75897 | 2026-08-20 | N/A | 7.5 HIGH | ||
| Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request. | |||||
| CVE-2026-20319 | 2026-08-20 | N/A | 7.5 HIGH | ||
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20319 are related to buffer management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-119. | |||||
| CVE-2026-20030 | 2026-08-20 | N/A | 10.0 CRITICAL | ||
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20030 are related to improper neutralization of special elements used in a SQL command issues that are grouped under the Common Weakness Enumeration (CWE) CWE-89. | |||||
| CVE-2026-56538 | 1 Hcltech | 1 Connections | 2026-08-20 | N/A | 3.5 LOW |
| An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users. | |||||
| CVE-2026-66641 | 2026-08-20 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions. | |||||
| CVE-2026-73387 | 2026-08-20 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Resido <= 1.5 versions. | |||||
| CVE-2026-28571 | 2026-08-20 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions. | |||||
| CVE-2026-73354 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions. | |||||
| CVE-2026-32481 | 2026-08-20 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions. | |||||
| CVE-2026-32552 | 2026-08-20 | N/A | 8.5 HIGH | ||
| Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions. | |||||
| CVE-2026-66603 | 2026-08-20 | N/A | 6.5 MEDIUM | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Artiss Draft List simple-draft-list allows Stored XSS. This issue affects Draft List: from n/a through 2.6.4. | |||||
| CVE-2026-28569 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions. | |||||
| CVE-2026-66645 | 2026-08-20 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions. | |||||
| CVE-2026-73363 | 2026-08-20 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions. | |||||
| CVE-2026-66602 | 2026-08-20 | N/A | 8.8 HIGH | ||
| Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0. | |||||
| CVE-2026-66643 | 2026-08-20 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions. | |||||
