Total
398833 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-58357 | 1 Surrealdb | 1 Surrealdb | 2026-08-12 | N/A | 6.5 MEDIUM |
| SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics when unwrap is called on a None result from timestamp_opt. Authorized clients can repeatedly invoke rand::time() to reliably trigger server panics and cause denial of service. | |||||
| CVE-2026-49743 | 3 Google, Imaginationtech, Linux | 3 Android, Ddk, Linux Kernel | 2026-08-12 | N/A | 7.8 HIGH |
| Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs. During workload submission involving a fence exported by the GPU driver, the reference count of the underlying synchronisation primitive is not properly incremented. This can be exploited, by destroying the exported fence and prematurely release the underlying primitive, resulting in a potential use-after-free condition. | |||||
| CVE-2026-49745 | 3 Google, Imaginationtech, Linux | 3 Android, Ddk, Linux Kernel | 2026-08-12 | N/A | 7.8 HIGH |
| Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges. | |||||
| CVE-2026-49744 | 3 Google, Imaginationtech, Linux | 3 Android, Ddk, Linux Kernel | 2026-08-12 | N/A | 7.8 HIGH |
| Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries. | |||||
| CVE-2026-16280 | 3 Google, Imaginationtech, Linux | 3 Android, Ddk, Linux Kernel | 2026-08-12 | N/A | 9.8 CRITICAL |
| An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memory corruption or information disclosure. | |||||
| CVE-2024-58358 | 1 Surrealdb | 1 Surrealdb | 2026-08-12 | N/A | 4.9 MEDIUM |
| SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles. Attackers can trigger an uncaught panic by signing in with a user assigned an invalid role, crashing the server. | |||||
| CVE-2026-9322 | 1 Ibm | 1 Websphere Application Server | 2026-08-12 | N/A | 7.5 HIGH |
| IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request. | |||||
| CVE-2024-58359 | 1 Surrealdb | 1 Surrealdb | 2026-08-12 | N/A | 6.5 MEDIUM |
| SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY rand() clause. Authorized clients can execute queries with ORDER BY rand() to trigger a panic in the sorting function, crashing the server. | |||||
| CVE-2024-58361 | 1 Surrealdb | 1 Surrealdb | 2026-08-12 | N/A | 6.5 MEDIUM |
| SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code when processing empty strings. Authorized clients can execute malformed queries with empty string conversions to record, duration, or datetime types that cause a panic in error rendering, crashing the server. | |||||
| CVE-2024-25039 | 1 Ibm | 1 Engineering Requirements Management Doors Web Access | 2026-08-12 | N/A | 7.5 HIGH |
| IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive. | |||||
| CVE-2025-0152 | 1 Ibm | 1 Engineering Requirements Management Doors Web Access | 2026-08-12 | N/A | 6.1 MEDIUM |
| IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |||||
| CVE-2024-40683 | 1 Ibm | 1 Operations Analytics - Log Analysis | 2026-08-12 | N/A | 6.3 MEDIUM |
| IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 does not invalidate session after a password chance which could allow an authenticated user to impersonate another user on the system. | |||||
| CVE-2026-23823 | 1 Arubanetworks | 1 Arubaos | 2026-08-12 | N/A | 7.2 HIGH |
| A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. NOTE: This vulnerability only impacts Access Points running AOS-10.7.x.x and above. AOS-10.4 AP and AOS-8 Instant software branches are not affected by this vulnerability. | |||||
| CVE-2026-23822 | 1 Arubanetworks | 1 Arubaos | 2026-08-12 | N/A | 5.3 MEDIUM |
| A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an attacker to cause excessive resource consumption upon user interaction, leading to service disruption or reduced availability of the affected system. NOTE: This vulnerability only impacts Access Points running AOS Instant 8.x.x.x | |||||
| CVE-2026-23821 | 1 Arubanetworks | 1 Arubaos | 2026-08-12 | N/A | 7.2 HIGH |
| A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. Note: Access Points running AOS-8 Instant software are not affected by this vulnerability. | |||||
| CVE-2026-23820 | 1 Arubanetworks | 1 Arubaos | 2026-08-12 | N/A | 7.2 HIGH |
| A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environment. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. | |||||
| CVE-2026-32992 | 1 Cpanel | 3 Cpanel, Whm, Wp Squared | 2026-08-12 | N/A | 8.2 HIGH |
| SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials. | |||||
| CVE-2024-58362 | 1 Surrealdb | 1 Surrealdb | 2026-08-12 | N/A | 8.8 HIGH |
| SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for non-computed values. When a record access method defines a SIGNIN or SIGNUP query and the RPC API is exposed to untrusted users, an unauthenticated attacker can encode a binary object containing a subquery using the bincode serialization format and supply it in place of credentials. The subquery is then executed within the database owner's SIGNIN/SIGNUP query under a system user session with the editor role, allowing the attacker to select, create, update, and delete non-IAM resources (though not view the query results directly, and not affect IAM resources, which require the owner role). | |||||
| CVE-2024-58363 | 1 Surrealdb | 1 Surrealdb | 2026-08-12 | N/A | 6.3 MEDIUM |
| SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method. Attackers with an authenticated session can impersonate an unrelated user in a different database if a user record with an identical identifier exists, allowing unauthorized actions if permissions rely solely on the $auth parameter. | |||||
| CVE-2026-50516 | 1 Microsoft | 1 Azure Kubernetes Service | 2026-08-12 | N/A | 9.4 CRITICAL |
| Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | |||||
