Common Vulnerabilities and Exposures (CVE)

CVE-2026-72570

Aug 10, 2026 17:51:17 UTC

A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to inject arbitrary JavaScript into the web interface by uploading a file with a crafted filename containing HTML attribute-brea...

CVE-2026-71393

Aug 10, 2026 17:50:19 UTC

GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. The function computes an allocation size using a 32-bit length value from a TrueType font file without overflow checking. On 32-bit targets,...

CVE-2026-13368

Aug 10, 2026 17:50:19 UTC

WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary co...

CVE-2026-72738

Aug 10, 2026 17:49:44 UTC

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoint in apps/dokploy/server/api/routers/backup.ts passes the search parameter through normalizeS3Path and interpolates it i...

CVE-2026-71394

Aug 10, 2026 17:49:37 UTC

GNU Emacs for Android improperly validates the table header input in sfnt_read_table_directory() in src/sfnt.c. Due to an incorrect comparison variable in the read-length check, a crafted font file that claims to contain more table director...

CVE-2026-71392

Aug 10, 2026 17:48:56 UTC

GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() function in src/sfnt.c. When processing a crafted TrueType font file, an unguarded addition in the xmalloc allocation call wraps around on 32-bit b...

CVE-2026-71391

Aug 10, 2026 17:48:11 UTC

GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index boundary check in sfnt_vary_simple_glyph() and sfnt_vary_compound_glyph() uses a strict greater-than comparison instead o...

CVE-2026-72737

Aug 10, 2026 17:47:50 UTC

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs in apps/dokploy/server/api/routers/backup.ts accept a client-controlled destinationId and u...

CVE-2026-66404

Aug 10, 2026 17:47:47 UTC

DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affected products may be retrieved.

CVE-2026-66403

Aug 10, 2026 17:47:06 UTC

DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.

CVE-2026-21083

Aug 10, 2026 17:45:40 UTC

Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.

CVE-2026-21072

Aug 10, 2026 17:44:52 UTC

Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

CVE-2026-21071

Aug 10, 2026 17:44:11 UTC

Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

CVE-2026-21070

Aug 10, 2026 17:43:25 UTC

Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.

CVE-2026-21084

Aug 10, 2026 17:42:44 UTC

Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information.