Total
398874 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2021-31979 | 1 Microsoft | 16 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 13 more | 2026-08-10 | 7.2 HIGH | 7.8 HIGH |
| Windows Kernel Elevation of Privilege Vulnerability | |||||
| CVE-2021-31196 | 1 Microsoft | 1 Exchange Server | 2026-08-10 | 6.5 MEDIUM | 7.2 HIGH |
| Microsoft Exchange Server Remote Code Execution Vulnerability | |||||
| CVE-2026-10569 | 1 Ibm | 2 Devops Deploy, Urbancode Deploy | 2026-08-10 | N/A | 4.3 MEDIUM |
| IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This exposure could allow an attacker with access to the logs to potentially obtain senstive values related to that step. | |||||
| CVE-2026-21662 | 1 Johnsoncontrols | 1 Fms Employee | 2026-08-10 | N/A | 9.8 CRITICAL |
| Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before 2025.3.1. | |||||
| CVE-2026-34490 | 1 Johnsoncontrols | 1 Xaap | 2026-08-10 | N/A | 5.5 MEDIUM |
| Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53. | |||||
| CVE-2026-34495 | 1 Johnsoncontrols | 1 Fms Employee | 2026-08-10 | N/A | 5.4 MEDIUM |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems Employee: before 2025.3.1. | |||||
| CVE-2026-34497 | 1 Johnsoncontrols | 1 Fms Employee | 2026-08-10 | N/A | 5.4 MEDIUM |
| Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue affects FM Systems Employee: before 2025.3.1. | |||||
| CVE-2026-10025 | 1 Ibm | 1 Qradar Security Information And Event Manager | 2026-08-10 | N/A | 8.2 HIGH |
| IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication. | |||||
| CVE-2026-12730 | 1 Ibm | 1 Business Automation Workflow | 2026-08-10 | N/A | 3.8 LOW |
| IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server. | |||||
| CVE-2026-12762 | 1 Ibm | 1 Business Automation Insights | 2026-08-10 | N/A | 5.3 MEDIUM |
| IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files. | |||||
| CVE-2026-15572 | 1 Redhat | 1 Build Of Keycloak | 2026-08-10 | N/A | 8.8 HIGH |
| A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker with client registration privileges can exploit this by first registering an allowed mapper type with a malicious configuration and then swapping it for a restricted, high-privilege mapper type (such as one that hardcodes administrative roles). This allows the attacker to gain full administrative access to the Keycloak realm. | |||||
| CVE-2026-16442 | 1 Redhat | 1 Build Of Keycloak | 2026-08-10 | N/A | 7.4 HIGH |
| A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account. | |||||
| CVE-2026-21570 | 1 Atlassian | 1 Bamboo | 2026-08-10 | N/A | 8.8 HIGH |
| This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.6, allows an authenticated attacker to execute malicious code on the remote system. Atlassian recommends that Bamboo Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Bamboo Data Center 9.6: Upgrade to a release greater than or equal to 9.6.24 Bamboo Data Center 10.2: Upgrade to a release greater than or equal to 10.2.16 Bamboo Data Center 12.1: Upgrade to a release greater than or equal to 12.1.3 See the release notes ([https://confluence.atlassian.com/bambooreleases/bamboo-release-notes-1189793869.html]). You can download the latest version of Bamboo Data Center from the download center ([https://www.atlassian.com/software/bamboo/download-archives]). This vulnerability was reported via our Atlassian (Internal) program. | |||||
| CVE-2026-18967 | 1 Redhat | 2 Build Of Keycloak, Jboss Enterprise Application Platform Expansion Pack | 2026-08-10 | N/A | 6.4 MEDIUM |
| A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it multiple times. Successful exploitation could allow an attacker to hijack a user's session and gain unauthorized access to the system as that user. | |||||
| CVE-2026-18569 | 1 Redhat | 1 Build Of Keycloak | 2026-08-10 | N/A | 3.7 LOW |
| A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC identity provider is configured to skip signature validation. In this specific setup, the system incorrectly accepts logout requests that have no cryptographic signature. An attacker who knows certain technical details about a user's session can use this flaw to force that user to be logged out, potentially disrupting their work. | |||||
| CVE-2026-14304 | 2 Eclipse, Soumu | 2 Accessibility Tools Framework, Michecker | 2026-08-10 | N/A | 5.5 MEDIUM |
| In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. | |||||
| CVE-2026-16443 | 1 Redhat | 1 Build Of Keycloak | 2026-08-10 | N/A | 7.4 HIGH |
| A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier. | |||||
| CVE-2026-41109 | 1 Microsoft | 1 Visual Studio Code | 2026-08-10 | N/A | 8.8 HIGH |
| Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network. | |||||
| CVE-2026-16389 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-10 | N/A | 9.8 CRITICAL |
| Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |||||
| CVE-2023-2008 | 1 Linux | 1 Linux Kernel | 2026-08-10 | N/A | 8.2 HIGH |
| A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler. This issue occurs due to the lack of proper validation of user-supplied data, which can result in memory access past the end of an array. This may allow an attacker to escalate privileges and execute arbitrary code in the context of the kernel. | |||||
