CVE-2026-59499 - Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE ID :CVE-2026-59499
Published : Aug. 13, 2026, 9:12 a.m. | 28 minutes ago
Description :CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59499
Published : Aug. 13, 2026, 9:12 a.m. | 28 minutes ago
Description :CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14298 - Denial of service via resource exhaustion in Mattermost
CVE ID :CVE-2026-14298
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit resource consumption when processing certain user-supplied input, which allows an authenticated user to cause a denial of service. Mattermost Advisory ID: MMSA-2026-00713
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14298
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit resource consumption when processing certain user-supplied input, which allows an authenticated user to cause a denial of service. Mattermost Advisory ID: MMSA-2026-00713
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14332 - Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.9 - Subscriber+ Store Disconnection via 'ec_disconnect' Action
CVE ID :CVE-2026-14332
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its store-management actions, allowing any authenticated user, such as a subscriber, to disconnect the store and take the storefront offline until an administrator reconnects it.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14332
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its store-management actions, allowing any authenticated user, such as a subscriber, to disconnect the store and take the storefront offline until an administrator reconnects it.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15413 - Link Factory - Backdoor
CVE ID :CVE-2026-15413
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check).
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-15413
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check).
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16458 - Timing side-channel in RSA PKCS#1 v1.5 decryption in ocrypto
CVE ID :CVE-2026-16458
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-16458
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16459 - Timing side-channel in RSA PKCS#1 v1.5 decryption in Oberon PSA Crypto
CVE ID :CVE-2026-16459
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-16459
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19481 - @fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header
CVE ID :CVE-2026-19481
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a part header whose name is a prototype-inherited property such as __proto__ or constructor. The internal header parser stores headers in a plain JavaScript object and assumes each value is an array, so an inherited property name resolves to a truthy non-array value and triggers a TypeError. In the common pipe integration the failure surfaces as an error event, but in direct write or end usage the exception is thrown synchronously and can terminate the Node.js process, causing an unauthenticated denial of service. The issue is fixed in @fastify/busboy 3.2.1, which creates the header object with a null prototype. Users should upgrade to 3.2.1.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19481
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a part header whose name is a prototype-inherited property such as __proto__ or constructor. The internal header parser stores headers in a plain JavaScript object and assumes each value is an array, so an inherited property name resolves to a truthy non-array value and triggers a TypeError. In the common pipe integration the failure surfaces as an error event, but in direct write or end usage the exception is thrown synchronously and can terminate the Node.js process, causing an unauthenticated denial of service. The issue is fixed in @fastify/busboy 3.2.1, which creates the header object with a null prototype. Users should upgrade to 3.2.1.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19694 - Heap-based Buffer Overflow in Wireshark
CVE ID :CVE-2026-19694
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19694
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19695 - Stack-based Buffer Overflow in Wireshark
CVE ID :CVE-2026-19695
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19695
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19696 - Out-of-bounds Write in Wireshark
CVE ID :CVE-2026-19696
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows
Severity: 6.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19696
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows
Severity: 6.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59500 - Priority - CWE-287: Improper Authentication
CVE ID :CVE-2026-59500
Published : Aug. 13, 2026, 9:18 a.m. | 22 minutes ago
Description :CWE-287: Improper Authentication
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59500
Published : Aug. 13, 2026, 9:18 a.m. | 22 minutes ago
Description :CWE-287: Improper Authentication
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-11970 - Forcepoint One Endpoint Safari Extension Disablement and DLP Bypass
CVE ID :CVE-2026-11970
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-11970
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59501 - Priority – CWE-284: Improper Access Control
CVE ID :CVE-2026-59501
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-284: Improper Access Control
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59501
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-284: Improper Access Control
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59502 - Priority - CWE-203: Observable Discrepancy
CVE ID :CVE-2026-59502
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-203: Observable Discrepancy
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59502
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-203: Observable Discrepancy
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59503 - Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
CVE ID :CVE-2026-59503
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59503
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59504 - Priority – CWE-602: Client-Side Enforcement of Server-Side Security
CVE ID :CVE-2026-59504
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-602: Client-Side Enforcement of Server-Side Security
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59504
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-602: Client-Side Enforcement of Server-Side Security
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59505 - Priority - CWE-284: Improper Access Control
CVE ID :CVE-2026-59505
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-284: Improper Access Control
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59505
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-284: Improper Access Control
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59506 - Priority – CWE-306: Missing Authentication for Critical Function
CVE ID :CVE-2026-59506
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-306: Missing Authentication for Critical Function
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59506
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-306: Missing Authentication for Critical Function
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59507 - Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control
CVE ID :CVE-2026-59507
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59507
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-45819 - baseline-browser-mapping Denial of Service Vulnerability
CVE ID :CVE-2026-45819
Published : Aug. 13, 2026, 11:03 a.m. | 37 minutes ago
Description :baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.
Severity: 6.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-45819
Published : Aug. 13, 2026, 11:03 a.m. | 37 minutes ago
Description :baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.
Severity: 6.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12263 - Authentication Bypass
CVE ID :CVE-2026-12263
Published : Aug. 13, 2026, 11:17 a.m. | 23 minutes ago
Description :Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-12263
Published : Aug. 13, 2026, 11:17 a.m. | 23 minutes ago
Description :Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...