Total
397529 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-82112 | 2026-08-28 | 4.0 MEDIUM | 3.5 LOW | ||
| A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src/index.ts of the component code_task_files. Executing a manipulation can lead to path traversal. The attack can be launched remotely. This patch is called 35d97bca0531894da36a85aedb95312da1bd5b7a. It is best practice to apply a patch to resolve this issue. | |||||
| CVE-2026-81851 | 2026-08-28 | N/A | N/A | ||
| A heap-based buffer overflow vulnerability in Fireware OS's iked process allows an authenticated administrator to crash the IKE daemon (iked), resulting in a denial of service, by saving a specially crafted configuration. | |||||
| CVE-2026-81848 | 2026-08-28 | 4.0 MEDIUM | 3.5 LOW | ||
| A vulnerability was determined in cyberchitta scrapling-fetch-mcp up to 0.2.2. The impacted element is the function s_fetch_page/s_fetch_pattern of the file src/scrapling_fetch_mcp/_fetcher.py. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. Upgrading to version 0.2.3 is sufficient to resolve this issue. This patch is called 9f6f34e92c55c3d95566ad9c62aca7327d24533a. Upgrading the affected component is advised. | |||||
| CVE-2026-81847 | 2026-08-28 | 6.5 MEDIUM | 5.5 MEDIUM | ||
| A vulnerability was found in MAA-AI MaaMCP up to 1.1.1.dev6+g2e4a41287. The affected element is the function save_pipeline/load_pipeline of the file pipeline_tools.py. Performing a manipulation results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named c93ef45cba75295eba26d9ff1ffb9202a91c6150. To fix this issue, it is recommended to deploy a patch. | |||||
| CVE-2026-81837 | 2026-08-28 | 7.5 HIGH | 6.3 MEDIUM | ||
| A flaw has been found in RooCodeInc Roo-Code up to 3.51.1. This issue affects the function path.resolve of the file src/core/tools/ApplyPatchTool.ts of the component ApplyPatchTool. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit has been published and may be used. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer. | |||||
| CVE-2026-81835 | 2026-08-28 | 6.5 MEDIUM | 5.5 MEDIUM | ||
| A security vulnerability has been detected in RooCodeInc Roo-Code up to 3.51.1. This affects the function fetch_instructions of the file malicious_mcp_server.py of the component MCP Integration Trust Model. The manipulation leads to code injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer. | |||||
| CVE-2026-81834 | 2026-08-28 | 7.5 HIGH | 6.3 MEDIUM | ||
| A weakness has been identified in RooCodeInc Roo-Code up to 3.51.1. Affected by this issue is the function ExecaTerminalProcess of the component README File Handler. Executing a manipulation can lead to code injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer. | |||||
| CVE-2026-81777 | 2026-08-28 | N/A | 5.3 MEDIUM | ||
| Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing. This issue affects Essential Addons for Elementor: from n/a through 6.8.0. | |||||
| CVE-2026-81767 | 2026-08-28 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions. | |||||
| CVE-2026-81761 | 2026-08-28 | N/A | 4.3 MEDIUM | ||
| Subscriber Broken Access Control in WpEvently <= 5.5.0 versions. | |||||
| CVE-2026-81760 | 2026-08-28 | N/A | 7.1 HIGH | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2. | |||||
| CVE-2026-81759 | 2026-08-28 | N/A | 5.4 MEDIUM | ||
| Contributor Broken Access Control in WpEvently <= 5.5.0 versions. | |||||
| CVE-2026-81757 | 2026-08-28 | N/A | 7.2 HIGH | ||
| Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions. | |||||
| CVE-2026-81299 | 2026-08-28 | N/A | 4.3 MEDIUM | ||
| Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions. | |||||
| CVE-2026-81285 | 2026-08-28 | N/A | 7.5 HIGH | ||
| Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions. | |||||
| CVE-2026-81284 | 2026-08-28 | N/A | 4.3 MEDIUM | ||
| Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions. | |||||
| CVE-2026-81276 | 2026-08-28 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions. | |||||
| CVE-2026-80433 | 2026-08-28 | N/A | 7.5 HIGH | ||
| Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions. | |||||
| CVE-2026-79988 | 2026-08-28 | N/A | N/A | ||
| The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities. | |||||
| CVE-2026-79256 | 1 Google | 2 Android, Chrome | 2026-08-28 | N/A | 8.3 HIGH |
| Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
