Total
397465 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-67860 | 2026-08-31 | N/A | 7.5 HIGH | ||
| open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend. | |||||
| CVE-2026-78078 | 2026-08-31 | N/A | N/A | ||
| Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 - Image uploads previously validated only file extension and basic size parameters. Non-image files disguised with raster extensions could be uploaded. Added strict MIME verification and GD binary raster decoding (imagecreatefromstring) to reject invalid/malformed images fail-closed. | |||||
| CVE-2026-67856 | 2026-08-31 | N/A | 7.5 HIGH | ||
| An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and DeleteSubscriptions requests | |||||
| CVE-2026-67687 | 2026-08-31 | N/A | 8.8 HIGH | ||
| Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java | |||||
| CVE-2026-53620 | 2026-08-31 | N/A | 6.3 MEDIUM | ||
| GROWI contains a vulnerability with an authorization bypass through user-controlled key in the bookmark folder APIs. If this vulnerability is exploited, an authenticated attacker could retrieve, tamper with, and/or delete the other user's bookmark data. | |||||
| CVE-2026-38708 | 2026-08-31 | N/A | 9.8 CRITICAL | ||
| TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the system.setclock interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input. | |||||
| CVE-2024-39024 | 2026-08-31 | N/A | 8.8 HIGH | ||
| In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution. | |||||
| CVE-2025-69948 | 2026-08-31 | N/A | 9.8 CRITICAL | ||
| SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1. | |||||
| CVE-2026-78076 | 2026-08-31 | N/A | N/A | ||
| Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10 - The AJAX endpoint save-megamenu-settings failed to enforce item-level and menu-level edit permissions (core.edit on com_menus.item.{id} or core.admin). An authenticated user could submit modified layout parameters for arbitrary menu items without proper authorization. | |||||
| CVE-2026-38447 | 2026-08-31 | N/A | 9.8 CRITICAL | ||
| osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window. | |||||
| CVE-2026-38444 | 2026-08-31 | N/A | 6.1 MEDIUM | ||
| osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitization in include/class.mailparse.php and stored raw in the poster field of ost_thread_entry. When an unauthenticated attacker sends a reply email to an existing ticket from an unregistered address with an XSS payload in the From display name. | |||||
| CVE-2025-14603 | 2026-08-31 | N/A | N/A | ||
| The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentially exposing database contents or causing the application to become unresponsive. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch. | |||||
| CVE-2025-59321 | 2026-08-31 | N/A | 9.8 CRITICAL | ||
| CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform. | |||||
| CVE-2026-0931 | 2026-08-31 | N/A | N/A | ||
| Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cause the M-Files Server process to crash and fail to restart. | |||||
| CVE-2026-67858 | 2026-08-31 | N/A | 7.5 HIGH | ||
| Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 request containing many unique discoveryUrls. This allows remote attackers to cause a denial of service. | |||||
| CVE-2026-55707 | 2026-08-31 | N/A | N/A | ||
| In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and altering L3 routing and address scope behavior for victim routers. | |||||
| CVE-2026-51144 | 2026-08-31 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via the Role Name, First Name, Last Name, and Username fields. | |||||
| CVE-2025-59319 | 2026-08-31 | N/A | 7.2 HIGH | ||
| CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high privilege. | |||||
| CVE-2025-14601 | 2026-08-31 | N/A | N/A | ||
| An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system commands due to insufficient input filtering. An attacker can exploit this flaw to disrupt web server operations, expose sensitive data, or potentially achieve full server compromise. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch. | |||||
| CVE-2026-52520 | 2026-08-31 | N/A | 5.4 MEDIUM | ||
| Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/article.php). A remote authenticated attacker can inject arbitrary JavaScript code via the article content. When an administrator reviews or previews the submitted article in the backend, the malicious script executes in the admin's browser session, allowing the attacker to perform administrative actions such as creating a backdoor administrator account. | |||||
