2026-08-12
2026-08-12 21:17Z
HIGH

CVE-2026-19002 — A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19002

A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver connects to, or the ability to respond in its place, in order to return malformed metadata. The resulting memory corruption may cause the client application to terminate abnormally or, under certain conditions, execute unintended CVSSv3.1 8.1 (HIGH)

CWECWE 120TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-12
2026-08-12 21:17Z
CRIT

CVE-2026-19001 — MongoDB: This may result in memory corruption within the calling application's process, leading to abnormal

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19001

The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and, under certain conditions, the potential for arbitrary code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 190VNDMongodbTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-12
2026-08-12 21:17Z
HIGH

CVE-2026-16033 — LXD: A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16033

A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (specifically affecting virtual machine / QEMU driver execution paths). An attacker can exploit this flaw by providing a crafted image archive with malicious template directives containing path traversal CVSSv3.1 8.5 (HIGH)

CWECWE 22VNDLxdTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-12
2026-08-12 21:17Z
HIGH

CVE-2026-13622 — A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13622

A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions can replace a migration proxy socket with a symlink to the host CRI-O socket. Beca CVSSv3.1 8.8 (HIGH)

CWECWE 22TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-12
2026-08-12 21:17Z
HIGH

CVE-2026-13433 — IBM: i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13433

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised code on the ACS user's workstation. CVSSv3.1 8.3 (HIGH)

CWECWE 494VNDIbmTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-12
2026-08-12 21:17Z
HIGH

CVE-2026-13105 — IBM: i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13105

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration. CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-12
2026-08-12 21:17Z
HIGH

CVE-2026-10543 — IBM: Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10543

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query. CVSSv3.1 8.2 (HIGH)

CWECWE 285VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-12
2026-08-12 20:17Z
HIGH

CVE-2026-73332 — CamaleonCMS: contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73332

CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the contact form edit endpoint, which lacks proper authorization controls. Attackers can persist malicious script payloads into the database that execute in victims' browsers when the contact form loads, enabling cookie theft, forged authen CVSSv3.1 8.7 (HIGH)

CWECWE 89VNDCamaleoncmsTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-12
2026-08-12 20:17Z
HIGH

CVE-2026-73329 — CamaleonCMS: contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73329

CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an administrator's browser by injecting unsanitized HTML payloads into the post title parameter during draft creation. Attackers can submit a malicious HTML payload as a draft title through the drafts creation endpoint, which is persisted to the database without escaping and later rendered as raw HTML in the admin drafts listing, e CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDCamaleoncmsTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-12
2026-08-12 20:17Z
HIGH

CVE-2026-73303 — Budibase: Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId without binding it

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73303

Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId without binding it to the authenticated session, while checking only currentEmail. An authenticated attacker who obtains a victim account identifier can start the email-change workflow for the victim, receive and submit the verification code through POST /api/v2/email/verification, move the victim email to an attacker-controlled addr CVSSv3.1 8.2 (HIGH)

CWECWE 639VNDBudibaseTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-12
2026-08-12 20:17Z
CRIT

CVE-2026-73269 — This allows the user to escalate their privileges from namespace-local access to cluster-wide control.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73269

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. This privilege escalation grants broad permissions, including the ability to access and manipulate secrets, manage cluster actions, and delete hosted clusters or n CVSSv3.1 9.9 (CRITICAL)

CWECWE 269TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-12
2026-08-12 20:17Z
CRIT

CVE-2026-73268 — Successful exploitation allows the injected Job to run with the controller's elevated privileges, leading

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73268

A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the spec.install.overrideJob raw extension. Successful exploitation allows the injected Job to run with the controller's elevated privileges, leading to arbitrary code CVSSv3.1 9.9 (CRITICAL)

CWECWE 94TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-12
2026-08-12 20:17Z
HIGH

CVE-2026-72809 — SiYuan: versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72809

SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any request whose RemoteAddr is loopback (127.0.0.1) for a specific set of endpoints (including /api/system/exit, getNetwork, getWorkspaceInfo, /assets/*, and /export/*). These localhost bypasses sit outside the access auth code gate, so they apply even when an access auth code is configured CVSSv3.1 8.0 (HIGH)

CWECWE 290VNDSiyuanTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-08-12
2026-08-12 20:17Z
HIGH

CVE-2026-72807 — SiYuan: versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72807

SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks function, which executes raw SQL using string substitution instead of parameterized queries. Attackers can distribute malicious SiYuan documents or packages with crafted template columns that execute arbitrary SQL on a victim's kernel when the package is imported and rendered, enabling read and write access across notebooks. CVSSv3.1 8.0 (HIGH)

CWECWE 89VNDSiyuanTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-08-12
2026-08-12 20:17Z
HIGH

CVE-2026-72804 — SiYuan: versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72804

SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing anonymous readers to retrieve block-level content of password-protected documents. Attackers can call these endpoints without supplying a password to read protected document content and the complete reference topology. CVSSv3.1 8.6 (HIGH)

CWECWE 200VNDSiyuanTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-12
2026-08-12 20:17Z
HIGH

CVE-2026-72798 — SiYuan: Attackers can request published databases that relate to restricted databases to retrieve sensitive content

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72798

SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell contents from hidden or password-protected databases. Attackers can request published databases that relate to restricted databases to retrieve sensitive content, or bypass row filtering entirely when the first column is a non-block type. CVSSv3.1 8.6 (HIGH)

CWECWE 862VNDSiyuanTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-12
2026-08-12 20:17Z
HIGH

CVE-2026-72795 — SiYuan: versions before v3.7.4 fail to filter embedded block content by publish access in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72795

SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. Attackers can request published blocks containing embed queries to read content from password-protected, hidden, or forbidden documents without authorization. CVSSv3.1 8.6 (HIGH)

CWECWE 862VNDSiyuanTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-12
2026-08-12 20:17Z
HIGH

CVE-2026-72794 — siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72794

siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthenticated users in publish mode. Attackers can retrieve the CookieKey value and forge valid session cookies to impersonate users or gain administrative access. CVSSv3.1 8.6 (HIGH)

CWECWE 522TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-12
2026-08-12 20:17Z
HIGH

CVE-2026-72793 — SiYuan: versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72793

SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the session-cookie signing key, OS username via pandoc path, and encrypted-notebook key material. Attackers can forge and tamper with session cookies to impersonate users, and on instances without access-auth codes configured, escalate to administrator privileges. CVSSv3.1 8.6 (HIGH)

CWECWE 522VNDSiyuanTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-12
2026-08-12 20:17Z
HIGH

CVE-2026-72789 — SiYuan: before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72789

SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypted notebooks through the publish API without authentication or key material. CVSSv3.1 8.6 (HIGH)

CWECWE 862VNDSiyuanTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-12
2026-08-12 20:17Z
CRIT

CVE-2026-72508 — This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72508

A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA). This enables the tenant to deploy arbitrary cluster-scoped resources, leading to privilege escalation and potential arbitrary code execution across the cluster. CVSSv3.1 9.9 (CRITICAL)

CWECWE 250TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-12
2026-08-12 20:17Z
CRIT

CVE-2026-63300 — An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63300

An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. When migrating an instance between projects, LXD fails to validate the instance's configuration against the target project's enforced restrictions (such as restricted.containers.lowlevel, restricted.devices.*, and restricted.network CVSSv3.1 9.9 (CRITICAL)

CWECWE 862TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-12
2026-08-12 20:17Z
CRIT

CVE-2026-63299 — LXD: An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63299

An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove function omits the limits.AllowVolumeCreation check before moving a volume across projects, and volume snapshot restore operations skip the AllowVolumeUpdate check when the configuration is nil (Config == nil). An attacker can exploit these fla CVSSv3.1 9.9 (CRITICAL)

CWECWE 770VNDLxdTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-12
2026-08-12 20:17Z
CRIT

CVE-2026-63298 — An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63298

An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon. CVSSv3.1 9.9 (CRITICAL)

CWECWE 78TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-12
2026-08-12 20:17Z
CRIT

CVE-2026-63297 — LXD: An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63297

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction checks before configuration merging is complete, creating a time-of-check to time-of-use (TOCTOU) condition. An attacker can exploit this flaw to copy instances with disallowed high-privilege configuration CVSSv3.1 9.9 (CRITICAL)

CWECWE 863CWECWE 367VNDLxdTYPVulnerability
9.9
CVSS v3.1
100
Edit Score