Common Vulnerabilities and Exposures (CVE)

CVE-2026-12372

Aug 12, 2026 17:48:54 UTC

A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, fail...

CVE-2026-69106

Aug 12, 2026 17:48:29 UTC

A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.

CVE-2026-68752

Aug 12, 2026 17:44:53 UTC

A Project Resource Manager may gain broader administrative privileges under specific conditions.

CVE-2026-42018

Aug 12, 2026 17:43:21 UTC

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

CVE-2024-26804

Aug 12, 2026 17:39:59 UTC

In the Linux kernel, the following vulnerability has been resolved: net: ip_tunnel: prevent perpetual headroom growth syzkaller triggered following kasan splat: BUG: KASAN: use-after-free in __skb_flow_dissect+0x19d1/0x7a50 net/core/flow_...

CVE-2026-15534

Aug 12, 2026 17:38:26 UTC

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each pa...

CVE-2024-31245

Aug 12, 2026 17:38:21 UTC

Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5.

CVE-2024-31249

Aug 12, 2026 17:36:54 UTC

Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725.

CVE-2026-16907

Aug 12, 2026 17:36:49 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bounds checking.

CVE-2026-17510

Aug 12, 2026 17:35:54 UTC

Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print_attribute() sizes the destination buffer for a BMPSTRING attribute from its declared byte...

CVE-2026-17248

Aug 12, 2026 17:35:51 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special elements in an OS command.

CVE-2026-61133

Aug 12, 2026 17:35:40 UTC

Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with ne...

CVE-2026-17271

Aug 12, 2026 17:35:22 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size.

CVE-2026-17218

Aug 12, 2026 17:35:04 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.

CVE-2026-12382

Aug 12, 2026 17:34:15 UTC

A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An...