Total
398710 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-19285 | 2026-08-14 | 4.3 MEDIUM | 5.3 MEDIUM | ||
| A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vulnerability is the function JsonMemoryStorage.createDomain/JsonMemoryStorage.getMemories/JsonMemoryStorage.saveMemories of the file src/tools/memoryTools.ts. The manipulation results in path traversal. The attack must be initiated from a local position. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet. | |||||
| CVE-2026-19270 | 2026-08-14 | 4.3 MEDIUM | 5.3 MEDIUM | ||
| A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function get_journey/delete_journey/analyze_journey/usage_stats of the file src/journey/JourneyStorage.ts of the component Journey/Usage. The manipulation of the argument journeyId/filename results in path traversal. The attack requires a local approach. The project was informed of the problem early through an issue report but has not responded yet. | |||||
| CVE-2026-19246 | 2026-08-14 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function _download_image_data_url of the file nanobot/providers/image_generation.py of the component Provider-returned Image URL Handler. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 5095. It is recommended to apply a patch to fix this issue. The vendor explains: "We confirm that provider-returned image URLs required the same SSRF protections applied to other network retrieval paths. (...) The patch is currently available on main and is planned for the next patch release, v0.3.1." | |||||
| CVE-2026-70315 | 1 Microsoft | 5 365 Apps, Microsoft 365, Office 2019 and 2 more | 2026-08-14 | N/A | 5.5 MEDIUM |
| Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | |||||
| CVE-2026-70314 | 1 Microsoft | 5 365 Apps, Microsoft 365, Office 2019 and 2 more | 2026-08-14 | N/A | 5.5 MEDIUM |
| Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally. | |||||
| CVE-2026-62882 | 1 Microsoft | 5 365 Apps, Office 2019, Office 2021 and 2 more | 2026-08-14 | N/A | 4.3 MEDIUM |
| Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-65661 | 1 Microsoft | 5 365 Apps, Office 2016, Office 2019 and 2 more | 2026-08-14 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-70337 | 1 Microsoft | 1 Powershell | 2026-08-14 | N/A | 8.8 HIGH |
| Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-70329 | 1 Microsoft | 5 365 Apps, Office 2019, Office 2021 and 2 more | 2026-08-14 | N/A | 8.8 HIGH |
| Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-65657 | 1 Microsoft | 5 365 Apps, Microsoft 365, Office 2019 and 2 more | 2026-08-14 | N/A | 7.8 HIGH |
| Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-64911 | 1 Microsoft | 5 365 Apps, Microsoft 365, Office 2019 and 2 more | 2026-08-14 | N/A | 7.8 HIGH |
| Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-63518 | 1 Microsoft | 6 365 Apps, Microsoft 365, Office 2019 and 3 more | 2026-08-14 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-63513 | 1 Microsoft | 6 365 Apps, Microsoft 365, Office 2016 and 3 more | 2026-08-14 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-13380 | 1 Vsee | 2 Clinic, Clinic Api | 2026-08-14 | N/A | 7.5 HIGH |
| VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is required to retrieve these credentials. An unauthenticated remote attacker who observes any of these HTTP responses on an instance where SFTP is configured can obtain the credentials and use them to access the associated SFTP server. | |||||
| CVE-2026-13381 | 1 Vsee | 2 Clinic, Clinic Api | 2026-08-14 | N/A | 8.1 HIGH |
| VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and delete files belonging to other users on the application server. | |||||
| CVE-2026-62910 | 1 Microsoft | 2 Exchange Server, Exchange Server Subscription Edition | 2026-08-14 | N/A | 7.2 HIGH |
| Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-62915 | 1 Microsoft | 2 Exchange Server, Exchange Server Subscription Edition | 2026-08-14 | N/A | 6.5 MEDIUM |
| Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. | |||||
| CVE-2026-62898 | 1 Microsoft | 3 .net, Visual Studio 2022, Visual Studio 2026 | 2026-08-14 | N/A | 7.5 HIGH |
| Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-64920 | 1 Microsoft | 5 365 Apps, Access, Office 2019 and 2 more | 2026-08-14 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-64905 | 1 Microsoft | 6 365 Apps, Microsoft 365, Office 2019 and 3 more | 2026-08-14 | N/A | 7.8 HIGH |
| Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |||||
