Common Vulnerabilities and Exposures (CVE)

CVE-2026-28166

Aug 24, 2026 11:54:47 UTC

Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.

CVE-2026-28165

Aug 24, 2026 11:54:47 UTC

Unauthenticated Privilege Escalation in Digits <= 9.2 versions.

CVE-2026-28162

Aug 24, 2026 11:54:46 UTC

Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.

CVE-2026-28153

Aug 24, 2026 11:54:45 UTC

Unauthenticated Broken Access Control in Notification Master &#8211; Real-Time WordPress Notifications With Email, SMS, Webhooks &amp; More <= 1.7.1 versions.

CVE-2026-28152

Aug 24, 2026 11:54:44 UTC

Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.

CVE-2026-28151

Aug 24, 2026 11:54:44 UTC

Unauthenticated Local File Inclusion in Tonda < 2.6 versions.

CVE-2026-66671

Aug 24, 2026 11:54:43 UTC

Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.

CVE-2026-71226

Aug 24, 2026 11:53:47 UTC

Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.

CVE-2026-55653

Aug 24, 2026 11:53:30 UTC

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group valid...

CVE-2026-48864

Aug 24, 2026 11:53:17 UTC

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` fil...

CVE-2026-6732

Aug 24, 2026 11:53:04 UTC

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a m...

CVE-2025-5318

Aug 24, 2026 11:52:51 UTC

A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle ...

CVE-2026-78323

Aug 24, 2026 11:50:28 UTC

A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust ...

CVE-2026-78246

Aug 24, 2026 11:48:26 UTC

A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown code of the file success/login.php of the component Admin Login. The manipulation of the argument Username leads to sql i...

CVE-2026-16313

Aug 24, 2026 11:47:10 UTC

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied...