Total
398710 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-43441 | 1 Apple | 5 Ipados, Iphone Os, Safari and 2 more | 2026-08-14 | N/A | 4.3 MEDIUM |
| The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash. | |||||
| CVE-2025-43433 | 1 Apple | 6 Ipados, Iphone Os, Safari and 3 more | 2026-08-14 | N/A | 8.8 HIGH |
| The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to memory corruption. | |||||
| CVE-2026-70325 | 1 Microsoft | 5 365 Apps, Microsoft 365, Office 2019 and 2 more | 2026-08-14 | N/A | 5.5 MEDIUM |
| Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | |||||
| CVE-2026-70320 | 1 Microsoft | 5 365 Apps, Microsoft 365, Office 2019 and 2 more | 2026-08-14 | N/A | 5.5 MEDIUM |
| Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | |||||
| CVE-2026-66806 | 1 Microsoft | 5 365 Apps, Office 2019, Office 2021 and 2 more | 2026-08-14 | N/A | 5.5 MEDIUM |
| Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |||||
| CVE-2026-70310 | 1 Microsoft | 6 365 Apps, Microsoft 365, Office 2019 and 3 more | 2026-08-14 | N/A | 5.5 MEDIUM |
| Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |||||
| CVE-2026-68809 | 1 Microsoft | 5 365 Apps, Office 2019, Office 2021 and 2 more | 2026-08-14 | N/A | 5.5 MEDIUM |
| Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | |||||
| CVE-2026-70316 | 1 Microsoft | 5 365 Apps, Microsoft 365, Office 2019 and 2 more | 2026-08-14 | N/A | 5.5 MEDIUM |
| Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | |||||
| CVE-2026-70319 | 1 Microsoft | 5 365 Apps, Microsoft 365, Office 2019 and 2 more | 2026-08-14 | N/A | 5.5 MEDIUM |
| Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |||||
| CVE-2026-70311 | 1 Microsoft | 6 365 Apps, Microsoft 365, Office 2019 and 3 more | 2026-08-14 | N/A | 7.8 HIGH |
| Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-65480 | 2026-08-14 | N/A | 6.5 MEDIUM | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem allows DOM-Based XSS. This issue affects TheGem: from n/a before 5.12.1.1. | |||||
| CVE-2026-57804 | 2026-08-14 | N/A | 7.5 HIGH | ||
| Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows PHP Local File Inclusion. This issue affects TheGem Theme Elements (for Elementor): from n/a before 5.12.1.1. | |||||
| CVE-2026-66810 | 1 Microsoft | 6 365 Apps, Microsoft 365, Office 2019 and 3 more | 2026-08-14 | N/A | 5.5 MEDIUM |
| Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |||||
| CVE-2026-73188 | 2026-08-14 | N/A | N/A | ||
| Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-13610. | |||||
| CVE-2026-28184 | 2026-08-14 | N/A | N/A | ||
| Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |||||
| CVE-2024-1139 | 2026-08-14 | N/A | 7.7 HIGH | ||
| A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a repository pull secret. | |||||
| CVE-2021-30120 | 1 Kaseya | 1 Vsa | 2026-08-14 | 5.0 MEDIUM | 9.9 CRITICAL |
| Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed description --- During the login process, after the user authenticates with username and password, the server sends a response to the client with the booleans MFARequired and MFAEnroled. If the attacker has obtained a password of a user and used an intercepting proxy (e.g. Burp Suite) to change the value of MFARequered from True to False, there is no prompt for the second factor, but the user is still logged in. | |||||
| CVE-2021-30119 | 1 Kaseya | 1 Vsa | 2026-08-14 | 3.5 LOW | 5.4 MEDIUM |
| Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Example request: `https://x.x.x.x/HelpDeskTab/rcResults.asp?result=<script>alert(document.cookie)</script>` The same is true for the parameter FileName of /done.asp Eaxmple request: `https://x.x.x.x/done.asp?FileName=";</script><script>alert(1);a="&PathData=&originalName=shell.aspx&FileSize=4388&TimeElapsed=00:00:00.078` | |||||
| CVE-2021-30116 | 1 Kaseya | 2 Vsa Agent, Vsa Server | 2026-08-14 | 7.5 HIGH | 10.0 CRITICAL |
| Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page is https://x.x.x.x/dl.asp When an attacker download a client for Windows and installs it, the file KaseyaD.ini is generated (C:\Program Files (x86)\Kaseya\XXXXXXXXXX\KaseyaD.ini) which contains an Agent_Guid and AgentPassword This Agent_Guid and AgentPassword can be used to log in on dl.asp (https://x.x.x.x/dl.asp?un=840997037507813&pw=113cc622839a4077a84837485ced6b93e440bf66d44057713cb2f95e503a06d9) This request authenticates the client and returns a sessionId cookie that can be used in subsequent attacks to bypass authentication. Security issues discovered --- * Unauthenticated download page leaks credentials * Credentials of agent software can be used to obtain a sessionId (cookie) that can be used for services not intended for use by agents * dl.asp accepts credentials via a GET request * Access to KaseyaD.ini gives an attacker access to sufficient information to penetrate the Kaseya installation and its clients. Impact --- Via the page /dl.asp enough information can be obtained to give an attacker a sessionId that can be used to execute further (semi-authenticated) attacks against the system. | |||||
| CVE-2017-11357 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-08-14 | 7.5 HIGH | 9.8 CRITICAL |
| Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code. | |||||
