Total
400462 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-13063 | 1 Mongodb | 1 Mongodb | 2026-08-05 | N/A | 4.3 MEDIUM |
| An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-memory condition by sending a crafted aggregation command. MongoDB's libmongocrypt library insufficiently validates payload-supplied values, which can result in an excessively large memory allocation. | |||||
| CVE-2026-13064 | 1 Mongodb | 1 Mongodb | 2026-08-05 | N/A | 6.5 MEDIUM |
| Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in affected MongoDB deployments, potentially leading to resource exhaustion. The resulting CPU-bound operation cannot be interrupted through standard administrative controls. | |||||
| CVE-2026-13065 | 1 Mongodb | 1 Mongodb | 2026-08-05 | N/A | 6.5 MEDIUM |
| A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate abnormally, resulting in denial of service. The issue stems from insufficient validation of sort specifications during execution. | |||||
| CVE-2026-13066 | 1 Mongodb | 1 Mongodb | 2026-08-05 | N/A | 6.5 MEDIUM |
| Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data returned to the client. This constitutes an unintended information disclosure affecting deployments that use server-side JavaScript. | |||||
| CVE-2026-13067 | 1 Mongodb | 1 Mongodb | 2026-08-05 | N/A | 6.3 MEDIUM |
| When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unintended role assignments following MONGODB-X509 authentication. Affected scenarios require local access to the proxy Unix domain socket and a valid X.509 certificate issued by a trusted certificate authority. | |||||
| CVE-2026-14519 | 1 Ibm | 1 App Connect Enterprise | 2026-08-05 | N/A | 7.5 HIGH |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a path traversal vulnerability. | |||||
| CVE-2026-14522 | 1 Ibm | 1 App Connect Enterprise | 2026-08-05 | N/A | 8.8 HIGH |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters. | |||||
| CVE-2026-56570 | 1 Hcltech | 1 Icontrol | 2026-08-05 | N/A | 3.7 LOW |
| HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers may enumerate valid usernames through browser suggestions. | |||||
| CVE-2026-15435 | 1 Ibm | 1 App Connect Enterprise | 2026-08-05 | N/A | 9.8 CRITICAL |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system. | |||||
| CVE-2026-56569 | 1 Hcltech | 1 Icontrol | 2026-08-05 | N/A | 4.0 MEDIUM |
| HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening. | |||||
| CVE-2026-39875 | 1 Apple | 1 Macos | 2026-08-05 | N/A | 7.8 HIGH |
| A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges. | |||||
| CVE-2026-10842 | 1 Ibm | 1 Websphere Application Server | 2026-08-05 | N/A | 7.5 HIGH |
| IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints. | |||||
| CVE-2026-13068 | 1 Mongodb | 1 Mongodb | 2026-08-05 | N/A | 4.2 MEDIUM |
| An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongoing query operations for other users. The behavior stems from an authorization check that does not correctly scope privileges to the appropriate namespace. | |||||
| CVE-2026-60602 | 1 Oracle | 1 Peoplesoft Enterprise Cs Student Financials | 2026-08-05 | N/A | 8.8 HIGH |
| Vulnerability in the PeopleSoft Enterprise CS Student Financials product of Oracle PeopleSoft (component: Billing). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Financials. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Student Financials. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). | |||||
| CVE-2026-60606 | 1 Oracle | 1 Peoplesoft Enterprise Cc Common Application Objects | 2026-08-05 | N/A | 9.1 CRITICAL |
| Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CC Common Application Objects accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CC Common Application Objects accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). | |||||
| CVE-2026-60607 | 1 Oracle | 1 Peoplesoft Enterprise Cs Financial Aid | 2026-08-05 | N/A | 5.5 MEDIUM |
| Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: FM Need Analysis Calculator). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise CS Financial Aid executes to compromise PeopleSoft Enterprise CS Financial Aid. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Financial Aid accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). | |||||
| CVE-2025-58468 | 1 Qnap | 1 Notification Center | 2026-08-05 | N/A | 8.8 HIGH |
| A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: Notification Center 1.10.0.3291 and later | |||||
| CVE-2026-60608 | 1 Oracle | 1 Peoplesoft Enterprise Cs Financial Aid | 2026-08-05 | N/A | 6.1 MEDIUM |
| Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Institutional Methodology Need Analysis). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise CS Financial Aid executes to compromise PeopleSoft Enterprise CS Financial Aid. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Financial Aid accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise CS Financial Aid accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N). | |||||
| CVE-2026-50261 | 2 Redhat, X.org | 3 Enterprise Linux, X Server, Xwayland | 2026-08-05 | N/A | 7.8 HIGH |
| A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root. | |||||
| CVE-2026-50260 | 2 Redhat, X.org | 3 Enterprise Linux, X Server, Xwayland | 2026-08-05 | N/A | 7.8 HIGH |
| A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root. | |||||
