Total
400203 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-14865 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-08-06 | N/A | 5.3 MEDIUM |
| In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion. | |||||
| CVE-2026-14902 | 1 Ivanti | 1 Xtraction | 2026-08-06 | N/A | 4.0 MEDIUM |
| An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs. | |||||
| CVE-2026-14932 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-08-06 | N/A | 6.5 MEDIUM |
| In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnerable to unauthenticated file read and deletion of image-extension files within the application directory. | |||||
| CVE-2026-14903 | 1 Ivanti | 1 Xtraction | 2026-08-06 | N/A | 7.7 HIGH |
| Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root. | |||||
| CVE-2026-12523 | 1 Cloudflare | 1 Quiche | 2026-08-06 | N/A | 7.5 HIGH |
| Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/3 frames. Impact HTTP/3 defines multiple frame types to support HTTP message exchanges and connection management. Each frame has a length and a payload whose length depends on the frame type. quiche was found to be vulnerable when parsing some frame types to pre-allocating memory based on the declared length. An attacker would not need to send the number of declared bytes to trigger this issue. In addition, quiche was found to not apply QPACK decompression limits correctly. This could allow an attacker to send specially crafted HEADERS frames that would cause more memory commitment than otherwise advertised by MAX_FIELD_SECTION_SIZE (configured by set_max_field_section_size()). Mitigation: * Users are requested to upgrade to quiche 0.29.3 which is the earliest version containing the fix for this issue. Credits: Disclosed responsibly by Sébastien Féry | |||||
| CVE-2026-58659 | 1 Lightningai | 1 Pytorch Lightning | 2026-08-06 | N/A | 7.8 HIGH |
| PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called. | |||||
| CVE-2026-66326 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 6.5 MEDIUM |
| Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-66325 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 6.1 MEDIUM |
| Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-66322 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 7.1 HIGH |
| Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-66321 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 7.4 HIGH |
| Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-66318 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 8.1 HIGH |
| Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-66317 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 5.4 MEDIUM |
| Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. | |||||
| CVE-2026-66316 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 5.4 MEDIUM |
| Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-66315 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 7.5 HIGH |
| Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-66314 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 6.5 MEDIUM |
| Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-66313 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 6.8 MEDIUM |
| Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. | |||||
| CVE-2026-66312 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 6.5 MEDIUM |
| Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | |||||
| CVE-2026-66311 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 6.2 MEDIUM |
| Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. | |||||
| CVE-2026-65804 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 6.1 MEDIUM |
| Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-54463 | 1 Faye | 1 Websocket-driver | 2026-08-06 | N/A | 7.5 HIGH |
| websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket protocol in websocket-driver include a length header that allows an arbitrarily large integer to be encoded as bytes with the high bit set, and a server or client can send an indefinite sequence of 0x80 or higher bytes that the peer parses into an ever-growing Ruby integer. This can make a WebSocket connection consume an unbounded amount of memory and lead to the host process running out of memory. This issue is fixed in version 0.8.1. | |||||
