Total
398563 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-28990 | 1 Apple | 6 Ipados, Iphone Os, Macos and 3 more | 2026-08-17 | N/A | 7.5 HIGH |
| The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing a maliciously crafted image may corrupt process memory. | |||||
| CVE-2026-28979 | 1 Apple | 4 Ipados, Iphone Os, Macos and 1 more | 2026-08-17 | N/A | 6.5 MEDIUM |
| An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash. | |||||
| CVE-2026-28973 | 1 Apple | 4 Ipados, Iphone Os, Macos and 1 more | 2026-08-17 | N/A | 8.6 HIGH |
| An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. A malicious app may be able to break out of its sandbox. | |||||
| CVE-2026-28958 | 1 Apple | 4 Ipados, Iphone Os, Macos and 1 more | 2026-08-17 | N/A | 5.5 MEDIUM |
| This issue was addressed with improved data protection. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. An app may be able to access sensitive user data. | |||||
| CVE-2026-28947 | 1 Apple | 6 Ipados, Iphone Os, Macos and 3 more | 2026-08-17 | N/A | 8.8 HIGH |
| A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |||||
| CVE-2026-13460 | 2 Ibm, Linux | 2 Storage Scale, Linux Kernel | 2026-08-17 | N/A | 7.5 HIGH |
| IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-node cluster communication and REST API authentication between GUI. | |||||
| CVE-2026-46731 | 1 Dell | 1 Display And Peripheral Manager | 2026-08-17 | N/A | 7.8 HIGH |
| Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution. | |||||
| CVE-2026-59914 | 1 Dell | 1 Display And Peripheral Manager | 2026-08-17 | N/A | 7.8 HIGH |
| Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution. | |||||
| CVE-2026-59916 | 1 Dell | 1 Display And Peripheral Manager | 2026-08-17 | N/A | 7.8 HIGH |
| Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution. | |||||
| CVE-2026-59917 | 1 Dell | 1 Display And Peripheral Manager | 2026-08-17 | N/A | 7.8 HIGH |
| Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution. | |||||
| CVE-2026-9198 | 1 Langflow | 1 Langflow | 2026-08-17 | N/A | 9.8 CRITICAL |
| IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments | |||||
| CVE-2026-73327 | 2026-08-17 | N/A | N/A | ||
| Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the reported behavior is intentional. The update process is designed to write files to disk and is restricted to the highest-privilege users working with cryptographically verified Joomla archives. | |||||
| CVE-2026-16887 | 1 Ibm | 1 I | 2026-08-17 | N/A | 7.5 HIGH |
| IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write. | |||||
| CVE-2026-16861 | 1 Ibm | 1 I | 2026-08-17 | N/A | 5.3 MEDIUM |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read. | |||||
| CVE-2026-16713 | 1 Ibm | 1 Documentation Offline | 2026-08-17 | N/A | 4.3 MEDIUM |
| IBM Documentation Offline 1.0.0 through 1.4.1 IBM Documentation could allow a remote attacker to obtain sensitive information due to a security misconfiguration where the documentation server binds to an unrestricted IP address. | |||||
| CVE-2025-10308 | 2026-08-17 | N/A | 4.3 MEDIUM | ||
| The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing nonce validation on the options deletion functionality. This makes it possible for unauthenticated attackers to delete all plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
| CVE-2026-59127 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-08-17 | N/A | 7.8 HIGH |
| Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-61925 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-08-17 | N/A | 7.8 HIGH |
| Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-61938 | 1 Microsoft | 4 Windows 11 24h2, Windows 11 25h2, Windows 11 26h1 and 1 more | 2026-08-17 | N/A | 7.0 HIGH |
| Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-62768 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-08-17 | N/A | 7.8 HIGH |
| Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | |||||
