Common Vulnerabilities and Exposures (CVE)

CVE-2026-20288

Aug 5, 2026 17:45:13 UTC

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate p...

CVE-2026-20301

Aug 5, 2026 17:45:13 UTC

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of servi...

CVE-2026-20294

Aug 5, 2026 17:45:13 UTC

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insuffic...

CVE-2026-20303

Aug 5, 2026 17:45:12 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that add...

CVE-2026-20310

Aug 5, 2026 17:45:12 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that add...

CVE-2026-20312

Aug 5, 2026 17:45:12 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that add...

CVE-2026-20289

Aug 5, 2026 17:45:12 UTC

A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker cou...

CVE-2026-20311

Aug 5, 2026 17:45:12 UTC

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is du...

CVE-2026-20313

Aug 5, 2026 17:45:11 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that add...

CVE-2026-10716

Aug 5, 2026 17:45:11 UTC

Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value ...

CVE-2026-67555

Aug 5, 2026 17:43:30 UTC

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service This issue affects Apache Qpid Proton-Dotnet: t...

CVE-2026-10128

Aug 5, 2026 17:42:08 UTC

IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite security controls intended to disable custom compo...

CVE-2026-51400

Aug 5, 2026 17:42:08 UTC

An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c

CVE-2026-70610

Aug 5, 2026 17:41:03 UTC

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the contextBridge boundary from untrusted content could carry ...

CVE-2026-70448

Aug 5, 2026 17:40:42 UTC

Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files.