| CVE-2026-81624 | HIGH | 7.5 | Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow h… | 2026-08-31 |
| CVE-2026-82659 | HIGH | 7.1 | nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw optio… | 2026-08-31 |
| CVE-2026-82660 | MEDIUM | 5.4 | Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normali… | 2026-08-31 |
| CVE-2026-82661 | MEDIUM | 5.4 | Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, all… | 2026-08-31 |
| CVE-2026-82662 | MEDIUM | 6.5 | Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized… | 2026-08-31 |
| CVE-2026-82664 | MEDIUM | 4.3 | A security vulnerability has been detected in yaojingang GEOFlow up to 2.1.0. This affects an unknown part of … | 2026-08-31 |
| CVE-2026-82665 | LOW | 3.8 | A vulnerability was detected in yaojingang GEOFlow up to 2.1.0. This vulnerability affects the function unlink… | 2026-08-31 |
| CVE-2026-82666 | MEDIUM | 4.7 | A flaw has been found in yaojingang GEOFlow up to 2.1.0. This issue affects the function preview of the file a… | 2026-08-31 |
| CVE-2026-82667 | MEDIUM | 4.7 | A vulnerability has been found in yaojingang GEOFlow up to 2.1.0. Impacted is the function DistributionControl… | 2026-08-31 |
| CVE-2026-82668 | HIGH | 7.3 | A security vulnerability has been detected in klaussilveira GitList 2.0.0. Affected by this vulnerability is t… | 2026-08-31 |
| CVE-2026-82853 | MEDIUM | 4.9 | Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option … | 2026-08-31 |
| CVE-2026-82854 | CRITICAL | 9.8 | Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size paramete… | 2026-08-31 |
| CVE-2026-82855 | CRITICAL | 9.8 | @hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and d… | 2026-08-31 |
| CVE-2026-82856 | CRITICAL | 9.8 | @hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in … | 2026-08-31 |
| CVE-2026-82857 | CRITICAL | 9.8 | hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM polic… | 2026-08-31 |
| CVE-2026-82858 | CRITICAL | 9.8 | @hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance val… | 2026-08-31 |
| CVE-2026-82859 | CRITICAL | 9.8 | hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:… | 2026-08-31 |
| CVE-2026-82860 | CRITICAL | 9.8 | @hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the a… | 2026-08-31 |
| CVE-2026-82861 | HIGH | 7.5 | @hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attackers to su… | 2026-08-31 |
| CVE-2026-82862 | HIGH | 8.4 | Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace f… | 2026-08-31 |
| CVE-2026-82863 | LOW | 3.3 | @hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing aud… | 2026-08-31 |
| CVE-2026-82864 | MEDIUM | 6.5 | pdfme pdf-lib versions before 5.5.10 contain an unbounded buffer growth vulnerability in the DecodeStream.ensu… | 2026-08-31 |
| CVE-2026-82865 | MEDIUM | 4.4 | pdfme schemas before 5.5.10 contains a cross-site scripting vulnerability in the multiVariableText property pa… | 2026-08-31 |
| CVE-2026-82866 | MEDIUM | 6.8 | @pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function… | 2026-08-31 |
| CVE-2026-82867 | MEDIUM | 6.1 | @pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the Select schema plugin that fai… | 2026-08-31 |
| CVE-2026-82868 | MEDIUM | 6.1 | @pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the SVG schema plugin that render… | 2026-08-31 |
| CVE-2026-82869 | HIGH | 7.7 | ToolJet Database versions before v3.16.44 contain a privilege escalation vulnerability in the join_tables endp… | 2026-08-31 |
| CVE-2026-82870 | CRITICAL | 9.6 | ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allo… | 2026-08-31 |
| CVE-2026-82871 | HIGH | 7.7 | ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authe… | 2026-08-31 |
| CVE-2026-82872 | CRITICAL | 9.1 | ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's works… | 2026-08-31 |
| CVE-2026-82873 | MEDIUM | 5.0 | ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/resources/ex… | 2026-08-31 |
| CVE-2026-82874 | CRITICAL | 9.9 | ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in th… | 2026-08-31 |
| CVE-2026-82875 | MEDIUM | 5.5 | ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that… | 2026-08-31 |
| CVE-2026-19873 | HIGH | 7.5 | HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the q… | 2026-08-31 |
| CVE-2026-49003 | CRITICAL | 9.6 | Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monit… | 2026-08-31 |
| CVE-2026-82669 | MEDIUM | 5.3 | A vulnerability was detected in klaussilveira GitList 2.0.0. Affected by this issue is the function SimpleXMLE… | 2026-08-31 |
| CVE-2026-82670 | MEDIUM | 4.4 | A flaw has been found in IObit Uninstaller 15.5.0.11. This affects the function IRP_MJ_DEVICE_CONTROL in the l… | 2026-08-31 |
| CVE-2026-82671 | LOW | 3.4 | A vulnerability has been found in IObit Unlocker 1.3.0.12. This vulnerability affects the function ZwTerminate… | 2026-08-31 |
| CVE-2026-82677 | LOW | 2.4 | A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the f… | 2026-08-31 |
| CVE-2026-82678 | MEDIUM | 4.7 | A vulnerability was identified in diem-project diem up to 5.1.3. The affected element is the function executeC… | 2026-08-31 |
| CVE-2026-82679 | MEDIUM | 6.3 | A security flaw has been discovered in diem-project diem up to 5.1.3. The impacted element is an unknown funct… | 2026-08-31 |
| CVE-2026-82680 | HIGH | 8.8 | A weakness has been identified in D-Link DSM-G600 1.01. This affects an unknown function of the file /load_fil… | 2026-08-31 |
| CVE-2026-82688 | CRITICAL | 9.1 | A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. Th… | 2026-08-31 |
| CVE-2026-82876 | HIGH | 8.2 | Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmw… | 2026-08-31 |
| CVE-2026-82877 | MEDIUM | 6.5 | ILIAS versions before 9.22, 10.0 through 10.9, and 11.0 through 11.2 contain an arbitrary file read vulnerabil… | 2026-08-31 |
| CVE-2026-82878 | MEDIUM | 6.3 | DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard l… | 2026-08-31 |
| CVE-2026-82879 | MEDIUM | 6.3 | DataEase before 2.10.26 contains multiple access control defects in the sharing link module. Tickets are not b… | 2026-08-31 |
| CVE-2026-82880 | HIGH | 7.5 | YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and… | 2026-08-31 |
| CVE-2026-82881 | MEDIUM | 5.4 | Aix-DB through 1.2.4 renders markdown with raw HTML enabled into v-html bindings without sanitization, allowin… | 2026-08-31 |
| CVE-2026-70449 | MEDIUM | 5.3 | Improper validation of resource URL attributes in Apache Wicket allows an unauthenticated remote attacker to r… | 2026-08-31 |