| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-11738 | Med | 0.29 | 4.4 | 0.00 | Aug 11, 2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality. | ||
| CVE-2026-11737 | Med | 0.29 | 4.5 | 0.00 | Aug 11, 2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality. | ||
| CVE-2026-11736 | Med | 0.32 | 4.9 | 0.01 | Aug 11, 2026 | A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality. | ||
| CVE-2026-11735 | Med | 0.32 | 4.9 | 0.01 | Aug 11, 2026 | A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality. | ||
| CVE-2026-11734 | Low | 0.18 | 2.7 | 0.01 | Aug 11, 2026 | A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable. | ||
| CVE-2026-11733 | Med | 0.32 | 4.9 | 0.01 | Aug 11, 2026 | A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device. | ||
| CVE-2025-31114 | Cri | 0.54 | — | 0.01 | Aug 11, 2026 | Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON. An attacker with access to the Fooocus web UI may be able to execute arbitrary code on the… | ||
| CVE-2026-73067 | Med | 0.37 | — | 0.00 | Aug 11, 2026 | Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init can cause SquishedDawg::read_squished_dawg in src/dict/dawg.cpp to accept an unterminated forward-edge run, after which SquishedDawg::Load calls… | ||
| CVE-2026-73066 | Med | 0.37 | — | 0.00 | Aug 11, 2026 | Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution… | ||
| CVE-2026-72925 | Med | 0.33 | 6.1 | 0.00 | Aug 11, 2026 | SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized attacker-controlled JSON in application/json and… | ||
| CVE-2026-72922 | Hig | 0.46 | 8.2 | 0.00 | Aug 11, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's autogpt_platform/backend/backend/api/features/integrations/router.py webhook_ingress_generic route selected… | ||
| CVE-2026-72921 | Hig | 0.46 | 8.1 | 0.00 | Aug 11, 2026 | SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling paths such as /tenant1234, /tenant1-old,… | ||
| CVE-2026-72920 | Cri | 0.57 | 9.8 | 0.01 | Aug 11, 2026 | SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser,… | ||
| CVE-2026-47702 | Cri | 0.52 | — | 0.00 | Aug 11, 2026 | TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the database as cleartext strings. An attacker who gains read access to the database (e.g., via SQL injection, backup exposure, or… | ||
| CVE-2026-18860 | Hig | 0.50 | 8.7 | 0.00 | Aug 11, 2026 | Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment. Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines… | ||
| CVE-2026-18636 | Med | 0.44 | 6.8 | 0.00 | Aug 11, 2026 | The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix check can be bypassed… | ||
| CVE-2026-18635 | Hig | 0.47 | 7.2 | 0.00 | Aug 11, 2026 | Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, the calling user needs to have the IMPERSONATE permission (usually only given to administrators). Velociraptor versions prior to… | ||
| CVE-2026-18129 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections. | ||
| CVE-2026-18127 | Hig | 0.50 | 7.7 | 0.01 | Aug 11, 2026 | External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage. | ||
| CVE-2026-18125 | Hig | 0.49 | 7.5 | 0.02 | Aug 11, 2026 | An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service. | ||
| CVE-2026-17535 | Med | 0.40 | 6.2 | 0.00 | Aug 11, 2026 | Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting the opportunity of attackers corrupting the… | ||
| CVE-2026-17061 | Cri | 0.65 | 10.0 | 0.01 | Aug 11, 2026 | A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution. | ||
| CVE-2023-54374 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2023-54373 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2023-54372 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2023-54371 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2023-54370 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2023-54369 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2023-54368 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2023-54367 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2022-50974 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2021-47995 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2021-47994 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2021-47993 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2021-47992 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2021-47991 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2021-47990 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2021-47989 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2021-47988 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2020-37265 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2020-37264 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2020-37263 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2020-37262 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2020-37261 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2020-37260 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2020-37259 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2020-37258 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2020-37257 | — | 0.00 | — | — | Aug 11, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2026-73210 | Med | 0.26 | — | 0.00 | Aug 11, 2026 | A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup option was enabled. PlaywrightCapture implements this option to prevent captures from accessing local, loopback, or otherwise non-public network resources.… | ||
| CVE-2026-51584 | Cri | 0.57 | 9.8 | 0.01 | Aug 11, 2026 | An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched only on an attacker-controllable identifier without binding to the IdP's… |
- risk 0.29cvss 4.4epss 0.00
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
- risk 0.29cvss 4.5epss 0.00
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality.
- risk 0.32cvss 4.9epss 0.01
A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.
- risk 0.32cvss 4.9epss 0.01
A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality.
- risk 0.18cvss 2.7epss 0.01
A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.
- risk 0.32cvss 4.9epss 0.01
A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.
- risk 0.54cvss —epss 0.01
Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON. An attacker with access to the Fooocus web UI may be able to execute arbitrary code on the…
- risk 0.37cvss —epss 0.00
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init can cause SquishedDawg::read_squished_dawg in src/dict/dawg.cpp to accept an unterminated forward-edge run, after which SquishedDawg::Load calls…
- risk 0.37cvss —epss 0.00
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution…
- risk 0.33cvss 6.1epss 0.00
SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized attacker-controlled JSON in application/json and…
- risk 0.46cvss 8.2epss 0.00
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's autogpt_platform/backend/backend/api/features/integrations/router.py webhook_ingress_generic route selected…
- risk 0.46cvss 8.1epss 0.00
SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling paths such as /tenant1234, /tenant1-old,…
- risk 0.57cvss 9.8epss 0.01
SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser,…
- risk 0.52cvss —epss 0.00
TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the database as cleartext strings. An attacker who gains read access to the database (e.g., via SQL injection, backup exposure, or…
- risk 0.50cvss 8.7epss 0.00
Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment. Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines…
- risk 0.44cvss 6.8epss 0.00
The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix check can be bypassed…
- risk 0.47cvss 7.2epss 0.00
Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, the calling user needs to have the IMPERSONATE permission (usually only given to administrators). Velociraptor versions prior to…
- risk 0.53cvss 8.1epss 0.01
Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.
- risk 0.50cvss 7.7epss 0.01
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.
- risk 0.49cvss 7.5epss 0.02
An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.
- risk 0.40cvss 6.2epss 0.00
Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting the opportunity of attackers corrupting the…
- risk 0.65cvss 10.0epss 0.01
A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.
- CVE-2023-54374Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2023-54373Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2023-54372Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2023-54371Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2023-54370Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2023-54369Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2023-54368Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2023-54367Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2022-50974Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2021-47995Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2021-47994Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2021-47993Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2021-47992Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2021-47991Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2021-47990Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2021-47989Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2021-47988Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2020-37265Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2020-37264Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2020-37263Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2020-37262Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2020-37261Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2020-37260Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2020-37259Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2020-37258Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2020-37257Aug 11, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- risk 0.26cvss —epss 0.00
A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup option was enabled. PlaywrightCapture implements this option to prevent captures from accessing local, loopback, or otherwise non-public network resources.…
- risk 0.57cvss 9.8epss 0.01
An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched only on an attacker-controllable identifier without binding to the IdP's…