Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 11 August 2026

RSS

1229 vulnerabilities published on 11 August 2026

Severity:
LiquidJS Templates Can Run Malicious Code
GHSA-gf2q-c269-pqgc CVE-2026-45618
LiquidJS templates can be used to execute arbitrary code, which means an attacker could potentially run their own code on a website or application that uses LiquidJS. This is a serious issue because i...
10.0
Adobe Campaign Classic Allows Malicious Code Execution
CVE-2026-71398
Adobe Campaign Classic's authorization system is flawed, allowing attackers to execute malicious code as the current user. This could lead to sensitive data being compromised or manipulated. Update Ad...
10.0
Adobe Campaign Classic: Unauthorized Code Execution
CVE-2026-27302
Adobe Campaign Classic allows unauthorized code to be executed by an attacker, potentially leading to data theft or system compromise. This vulnerability can be exploited without requiring user intera...
10.0
ColdFusion | Unapproved Code Execution Risk
CVE-2026-48362
An attacker can run unauthorized code on your ColdFusion server without needing user interaction, potentially causing damage or disruption. This vulnerability affects ColdFusion, a software used to bu...
10.0
SIMULIA Execution Engine: Unauthenticated Remote Code Execution
CVE-2026-17061
The SIMULIA Execution Engine, used in certain software, has a vulnerability that allows attackers to run unauthorized code remotely without needing a password. This could lead to unauthorized access a...
10.0
Streambert Vulnerable to Malicious File Execution
CVE-2026-48056
Streambert, a video streaming app, has a security issue where a hacker could run any program on your computer with the app's permissions. This is a concern because it could lead to data theft or syste...
10.0
SIMATIC IoT2050 Advanced: Unauthenticated Access to System Commands
CVE-2026-58115
Certain versions of SIMATIC IoT2050 Advanced without the latest security patch allow unauthenticated remote access to programming nodes that can execute system commands. This could let an attacker run...
10.0
SAP Commerce Cloud Data Hub Adapter Authentication Bypass
CVE-2026-58231
An attacker without a login can potentially execute unauthorized code in SAP Commerce Cloud's Data Hub Adapter, compromising internal components and putting sensitive data at risk. This is a serious i...
10.0
TypeBot versions prior to 3.17.0: OAuth credential takeover risk
CVE-2026-48765
Versions of TypeBot before 3.17.0 are vulnerable to an attacker taking control of a workspace's OAuth credentials. This could happen if an attacker has limited access to a workspace and can view its s...
9.9
n8n versions before 2.32.1 allow hackers to run system commands
CVE-2026-72765
An attacker with permission to edit workflows in n8n can potentially run system commands on the server, which could lead to unauthorized access or data loss. This issue has been fixed in versions 2.31...
8.7
WireGuard Easy: Malicious Commands Can Be Executed as Root
CVE-2026-72603
An attacker with permission to create new clients in WireGuard Easy can inject malicious commands into the system by exploiting a vulnerability in the software. This allows them to execute commands wi...
9.9
n8n: Authenticated users can run system commands
GHSA-gv7g-jm28-cr3m CVE-2026-72765
An authenticated user with permission to edit workflows can execute system commands on the host running n8n, potentially leading to unauthorized actions. To fix this, update to n8n version 2.31.5 or l...
9.4
Rclone: Unauthenticated Command Execution via Remote API
DEBIAN-CVE-2026-49980 ROOT-APP-GOBINARY-CVE-2026-49980 GHSA-qw24-gh76-8rvv CVE-2026-49980
Rclone's remote control API allows an attacker to execute commands as the Rclone process user without authentication. This is a risk for any network-facing Rclone installation that uses the `--rc-serv...
9.8
Mira Android App Passwords Not Verified Correctly
CVE-2026-68067
The Mira Android app has a weak password verification system. This means an attacker could use an email address to access hormone records and account settings. To stay secure, update the app to the la...
9.3
RClone: Unauthenticated Access to Remote Control API Exposes Local Command Execution
GHSA-jfwf-28xr-xw6q CVE-2026-41179 BIT-rclone-2026-41179 GO-2026-5466
An attacker without a password can access the RClone remote control API and execute local commands on your system. This can happen if you're using the `--rc` flag or running the `rclone rcd` server an...
9.9
Formidable Digital Signatures <= 3.0.6 - Unauthenticated File Deletion
CVE-2026-16230
An attacker can delete files on your server without needing a password. This affects the Formidable Digital Signatures plugin for WordPress. To fix this, update the plugin to version 3.0.7 or later.
9.8
DB-GPT v0.8.1 allows attackers to write files anywhere on server
CVE-2026-73034
The DB-GPT software has a security flaw that lets attackers upload files to any location on the server. This could allow attackers to take control of the server, so it's essential to update to a secur...
9.3
PeerTube: Unauthenticated SQL injection allows database takeover
CVE-2026-73211
PeerTube's database security was compromised, allowing unauthorized access to sensitive data and administrative accounts. This issue has been fixed in version 8.1.6, so update your PeerTube installati...
9.8
MaxKey Hard-coded JWT Secret Allows Unauthorized Access
CVE-2026-69102
MaxKey's login system has a secret key stored in plain sight, making it easy for attackers to create fake login tokens. This allows anyone to log in as any user, including administrators, and access s...
9.3
ManageEngine DDI Central Password Reset Bypass
CVE-2026-12571
A security issue in ManageEngine DDI Central allows attackers to bypass the password reset process, potentially taking control of user accounts. This could lead to unauthorized access to sensitive dat...
9.8
Windows iSCSI Target Service Remote Code Execution
CVE-2026-65791
The Windows iSCSI Target Service is affected by a vulnerability that could allow an attacker to execute malicious code on a computer from another network location. This could potentially allow an atta...
9.8
Windows Deployment Services TFTP Server Code Execution Risk
CVE-2026-62893
An attacker can execute malicious code on a Windows Deployment Services server, potentially taking control of the server. This could allow the attacker to access sensitive information or disrupt servi...
9.8
Windows DNS Server Remote Code Execution
CVE-2026-62878
An attacker can execute malicious code on your DNS server if they gain access to it. This is a serious concern because an attacker could then access and control your network. To protect yourself, ensu...
9.8
Microsoft QUIC allows unauthorized code execution over networks
CVE-2026-62815
Microsoft's QUIC protocol is affected, which can be exploited by attackers to run malicious code on vulnerable systems. This could lead to unauthorized access and data theft. Microsoft will likely rel...
9.8
Microsoft HPC Pack Remote Code Execution Risk
CVE-2026-59124
Microsoft HPC Pack's ability to execute code can be exploited by unauthorized users over a network, potentially allowing them to access or modify sensitive data. This is a serious risk because it coul...
9.8