CVE-2026-18622 - Foxit PDF Editor/Reader's signature-validation pop-up reports modified certified documents as valid
CVE ID :CVE-2026-18622
Published : Aug. 13, 2026, 7:17 a.m. | 22 minutes ago
Description :Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18622
Published : Aug. 13, 2026, 7:17 a.m. | 22 minutes ago
Description :Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-11840 - SQL Injection
CVE ID :CVE-2026-11840
Published : Aug. 13, 2026, 8:16 a.m. | 1 hour, 24 minutes ago
Description :Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-11840
Published : Aug. 13, 2026, 8:16 a.m. | 1 hour, 24 minutes ago
Description :Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-3639 - PPWP – Password Protect Pages <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
CVE ID :CVE-2026-3639
Published : Aug. 13, 2026, 8:16 a.m. | 1 hour, 23 minutes ago
Description :The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in all versions up to, and including, 1.9.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-3639
Published : Aug. 13, 2026, 8:16 a.m. | 1 hour, 23 minutes ago
Description :The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in all versions up to, and including, 1.9.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19484 - @fastify/busboy vulnerable to Denial of Service via oversized multipart boundary
CVE ID :CVE-2026-19484
Published : Aug. 13, 2026, 8:50 a.m. | 49 minutes ago
Description :@fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop by sending a multipart request whose boundary is crafted to a specific length. The vendored streaming search stores its skip table in a fixed 256 entry byte array, and a boundary of exactly 252 bytes makes the search needle 256 bytes, which truncates the default skip distance to zero and turns the search into a CPU bound loop on a small body. A single small request can keep one core busy and deny service to other requests handled by the same process. The issue is fixed in @fastify/busboy 3.2.1, which widens the skip table so the skip distance is preserved. Users should upgrade to 3.2.1.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19484
Published : Aug. 13, 2026, 8:50 a.m. | 49 minutes ago
Description :@fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop by sending a multipart request whose boundary is crafted to a specific length. The vendored streaming search stores its skip table in a fixed 256 entry byte array, and a boundary of exactly 252 bytes makes the search needle 256 bytes, which truncates the default skip distance to zero and turns the search into a CPU bound loop on a small body. A single small request can keep one core busy and deny service to other requests handled by the same process. The issue is fixed in @fastify/busboy 3.2.1, which widens the skip table so the skip distance is preserved. Users should upgrade to 3.2.1.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59499 - Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE ID :CVE-2026-59499
Published : Aug. 13, 2026, 9:12 a.m. | 28 minutes ago
Description :CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59499
Published : Aug. 13, 2026, 9:12 a.m. | 28 minutes ago
Description :CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14298 - Denial of service via resource exhaustion in Mattermost
CVE ID :CVE-2026-14298
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit resource consumption when processing certain user-supplied input, which allows an authenticated user to cause a denial of service. Mattermost Advisory ID: MMSA-2026-00713
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14298
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit resource consumption when processing certain user-supplied input, which allows an authenticated user to cause a denial of service. Mattermost Advisory ID: MMSA-2026-00713
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14332 - Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.9 - Subscriber+ Store Disconnection via 'ec_disconnect' Action
CVE ID :CVE-2026-14332
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its store-management actions, allowing any authenticated user, such as a subscriber, to disconnect the store and take the storefront offline until an administrator reconnects it.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14332
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its store-management actions, allowing any authenticated user, such as a subscriber, to disconnect the store and take the storefront offline until an administrator reconnects it.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15413 - Link Factory - Backdoor
CVE ID :CVE-2026-15413
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check).
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-15413
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check).
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16458 - Timing side-channel in RSA PKCS#1 v1.5 decryption in ocrypto
CVE ID :CVE-2026-16458
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-16458
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16459 - Timing side-channel in RSA PKCS#1 v1.5 decryption in Oberon PSA Crypto
CVE ID :CVE-2026-16459
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-16459
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19481 - @fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header
CVE ID :CVE-2026-19481
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a part header whose name is a prototype-inherited property such as __proto__ or constructor. The internal header parser stores headers in a plain JavaScript object and assumes each value is an array, so an inherited property name resolves to a truthy non-array value and triggers a TypeError. In the common pipe integration the failure surfaces as an error event, but in direct write or end usage the exception is thrown synchronously and can terminate the Node.js process, causing an unauthenticated denial of service. The issue is fixed in @fastify/busboy 3.2.1, which creates the header object with a null prototype. Users should upgrade to 3.2.1.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19481
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a part header whose name is a prototype-inherited property such as __proto__ or constructor. The internal header parser stores headers in a plain JavaScript object and assumes each value is an array, so an inherited property name resolves to a truthy non-array value and triggers a TypeError. In the common pipe integration the failure surfaces as an error event, but in direct write or end usage the exception is thrown synchronously and can terminate the Node.js process, causing an unauthenticated denial of service. The issue is fixed in @fastify/busboy 3.2.1, which creates the header object with a null prototype. Users should upgrade to 3.2.1.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19694 - Heap-based Buffer Overflow in Wireshark
CVE ID :CVE-2026-19694
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19694
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19695 - Stack-based Buffer Overflow in Wireshark
CVE ID :CVE-2026-19695
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19695
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19696 - Out-of-bounds Write in Wireshark
CVE ID :CVE-2026-19696
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows
Severity: 6.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19696
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows
Severity: 6.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59500 - Priority - CWE-287: Improper Authentication
CVE ID :CVE-2026-59500
Published : Aug. 13, 2026, 9:18 a.m. | 22 minutes ago
Description :CWE-287: Improper Authentication
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59500
Published : Aug. 13, 2026, 9:18 a.m. | 22 minutes ago
Description :CWE-287: Improper Authentication
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-11970 - Forcepoint One Endpoint Safari Extension Disablement and DLP Bypass
CVE ID :CVE-2026-11970
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-11970
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59501 - Priority – CWE-284: Improper Access Control
CVE ID :CVE-2026-59501
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-284: Improper Access Control
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59501
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-284: Improper Access Control
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59502 - Priority - CWE-203: Observable Discrepancy
CVE ID :CVE-2026-59502
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-203: Observable Discrepancy
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59502
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-203: Observable Discrepancy
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59503 - Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
CVE ID :CVE-2026-59503
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59503
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59504 - Priority – CWE-602: Client-Side Enforcement of Server-Side Security
CVE ID :CVE-2026-59504
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-602: Client-Side Enforcement of Server-Side Security
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59504
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-602: Client-Side Enforcement of Server-Side Security
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59505 - Priority - CWE-284: Improper Access Control
CVE ID :CVE-2026-59505
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-284: Improper Access Control
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59505
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-284: Improper Access Control
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...