Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 5 August 2026

RSS

919 vulnerabilities published on 5 August 2026

Severity:
PraisonAI: Unsecured GitHub Actions Workflow Exposes GitHub Data
CVE-2026-48168
PraisonAI's GitHub Actions workflow is vulnerable to attacks if an unauthorized contributor submits a pull request with malicious branch name and comments '@claude'. This could allow them to manipulat...
10.0
WooCommerce Custom Fields < 1.5.1: Unauthenticated File Deletion Risk
CVE-2026-16940
A security flaw in WooCommerce Custom Fields versions before 1.5.1 allows anyone to delete any file on the server, potentially giving them control of the entire website. This is a serious issue becaus...
10.0
boringproxy 0.10.0 allows unauthorized SSH access
CVE-2026-70615
An attacker can gain persistent access to a boringproxy server by manipulating the SSH settings. This could allow them to read sensitive information such as user credentials and keys. To fix this, upd...
8.5
Cisco Catalyst SD-WAN Input Validation Weakness
CVE-2026-20303
Cisco Catalyst SD-WAN software has a weakness in how it checks user input. This means an attacker could potentially manipulate data to cause issues. Cisco has released an update to fix this issue, and...
9.9
Cisco Catalyst SD-WAN Access Control Flaw Exposes Network
CVE-2026-20304
Cisco Catalyst SD-WAN software has an access control issue that could allow unauthorized users to access sensitive parts of the network. This is a security concern because it could lead to unauthorize...
9.9
Progress MarkLogic Server Hadoop Privilege Escalation
CVE-2026-9193
A security issue in Progress MarkLogic Server's Hadoop integration allows a user with limited access to gain more power and access sensitive areas. This affects versions before 11.3.6 and 12.0.3. To s...
9.9
Progress MarkLogic Server: Low-Privilege User Escalation via Patch Operation
CVE-2026-8709
A vulnerability in Progress MarkLogic Server's REST API document patch operation allows a low-privileged user to gain more access. This could allow an unauthorized user to make changes to sensitive da...
9.9
MarkLogic Server: Privilege Escalation via Low-Privileged User
CVE-2026-7329
An authenticated user with limited access to MarkLogic Server can gain full administrator privileges, allowing them to access and modify sensitive data. This vulnerability affects versions before 11.3...
9.9
OpenPLC Runtime v3 Allows Unauthorized File Writes
CVE-2026-71268
An attacker can write files to arbitrary locations on the system using OpenPLC Runtime v3. This can potentially lead to remote code execution. It's essential to update OpenPLC to the latest version an...
9.9
OpenShift Container Platform 4.9.56 Security Update: Unpatched Vulnerability Exposed
RHSA-2023:0777
A security update has been released for OpenShift Container Platform 4.9.56, which fixes a previously unknown vulnerability. This vulnerability could allow an attacker to access sensitive data or take...
9.9
IBM Application Gateway Operator allows attackers to control requests
CVE-2026-17617
IBM Application Gateway Operator, used to manage IBM Application Gateway, is vulnerable to a security issue that allows attackers to send unauthorized requests. This could lead to sensitive data expos...
9.8
Cisco IOS XE Software: Improper Input Validation
CVE-2026-20272
Cisco IOS XE Software has identified and fixed several security issues that could allow an attacker to manipulate data. This affects the security of your network, and you should apply the latest softw...
9.8
MarkLogic Server ODBC App Server Allows Unauthenticated Access
CVE-2026-9192
An older version of MarkLogic Server's ODBC App Server can be exploited by an attacker to access the server without a password. This means an attacker can run queries with the same permissions as a se...
9.8
IBM QRadar SIEM allows unauthorized access through XML data
CVE-2026-10025
IBM QRadar SIEM versions 7.5 and 7.6 have a vulnerability that can allow attackers to access the system using specially crafted XML data. This could potentially allow unauthorized access to the system...
9.8
NASA-AMMOS ANMS Exposes Management API to the Internet
CVE-2026-71289
A default configuration in NASA-AMMOS's Asynchronous Network Management System (ANMS) exposes its management API to the internet, allowing anyone to access sensitive information and send commands to c...
9.8
Unauthenticated Script Execution in rust-iot-platform
CVE-2026-71278
An attacker can create a malicious script and execute it on the server without logging in. This can lead to unauthorized access and potentially cause harm to the system. To fix this, ensure that all r...
9.8
microtar: Stack Buffer Overflow in Filename Handling
CVE-2026-71267
The microtar library has a bug that can cause a crash when handling very long filenames. This bug can be exploited by an attacker to make the program crash or execute malicious code. To fix this, upda...
9.8
IoTSharp BlobStorageController lacks authentication, allowing unauthorized access
CVE-2026-71262
The IoTSharp BlobStorageController is not secure because it doesn't require authentication, making it accessible to anyone. This can lead to unauthorized access to and manipulation of files, potential...
9.8
nanoMODBUS: Malicious Server Can Write to Arbitrary Memory Locations
CVE-2026-71256
A vulnerability in nanoMODBUS versions 1.23.0 and earlier allows a malicious Modbus server to potentially write to any location in memory, leading to unintended behavior or data corruption. This issue...
9.8
nanoMODBUS Server Denial of Service or Remote Code Execution
CVE-2026-71254
An attacker can send a specific request to a nanoMODBUS server, causing it to write data outside its memory boundaries. This could lead to the server crashing or potentially allowing an attacker to ex...
9.8
Zbtlink Router Has Root Access Implant
CVE-2026-66747
The Zbtlink router has a hidden program that allows an attacker to control the router remotely without a password. This could allow an attacker to make changes to the router's settings or even take co...
9.3
Inventory-Management-System-PHP: Unauthenticated Product Deletion and Login Bypass
CVE-2026-71248
An attacker can delete products without permission and bypass login security. This is a serious issue because it allows unauthorized access to sensitive data and actions. Update the software to fix th...
9.8
Miantang IoT-PHP: Unauthenticated Password Bypass and Data Theft
CVE-2026-71237
Miantang IoT-PHP's login feature is vulnerable to unauthorized access. An attacker can bypass the login system and extract sensitive data from the database. To protect your system, update Miantang IoT...
9.8
IOTSmartHome: Unauthenticated SQL Injection via Cookie
CVE-2026-71231
IOTSmartHome's login system is vulnerable to a security attack that allows an unauthorized user to access user data. This is because the system doesn't properly check the data sent by the user's brows...
9.8
Apache Lucy: Untrusted Data Can Crash the Server
CVE-2026-61484
Apache Lucy is a retired project, which means it won't receive any updates or fixes. This means that all versions of Apache Lucy are vulnerable to a security issue that can cause the server to crash. ...
9.8