Common Vulnerabilities and Exposures (CVE)

CVE-2026-21069

Aug 10, 2026 17:42:03 UTC

Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

CVE-2026-21068

Aug 10, 2026 17:41:01 UTC

Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.

CVE-2026-72736

Aug 10, 2026 17:40:44 UTC

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands via unquoted template literal interpolation in the registry credential testing and Docker Sw...

CVE-2026-21082

Aug 10, 2026 17:39:56 UTC

Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.

CVE-2026-64940

Aug 10, 2026 17:39:20 UTC

Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a resul...

CVE-2026-21081

Aug 10, 2026 17:39:06 UTC

Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.

CVE-2026-57279

Aug 10, 2026 17:38:37 UTC

Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of a user logged in to the product.

CVE-2026-10754

Aug 10, 2026 17:38:01 UTC

Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.

CVE-2026-12570

Aug 10, 2026 17:37:39 UTC

A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving/sa...

CVE-2026-19375

Aug 10, 2026 17:36:44 UTC

A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0. This vulnerability affects the function fetch_article of the file news_scraper_mcp/server.py. The manipulation of the argument url results in server-side request forgery....

CVE-2026-70622

Aug 10, 2026 17:35:23 UTC

tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an attacker-contro...

CVE-2026-72735

Aug 10, 2026 17:34:36 UTC

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/src/utils/traefik/application.ts serializes user-controlled Traefik configuration with yaml.stringify and interpola...

CVE-2026-21080

Aug 10, 2026 17:31:12 UTC

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.

CVE-2026-13722

Aug 10, 2026 17:31:01 UTC

WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. An authenticated administrator can exploit this vulnerability to install a tampered firmware image.

CVE-2026-16232

Aug 10, 2026 17:30:29 UTC

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful e...