Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 12 August 2026
RSS784 vulnerabilities published on 12 August 2026
Severity:
IBM DOORS Next: Unauthorized Access to Sensitive Data
CVE-2024-27253
IBM DOORS Next is affected by a security weakness that allows an authenticated user to access data they shouldn't have. This could lead to unauthorized changes or disclosure of sensitive information. ...
10.0
SeaweedFS allows attackers to access unauthorized data
CVE-2026-54917
CVE-2026-58372
GHSA-w62w-66v9-vvgv
SeaweedFS, a distributed storage system, has a security issue that allows attackers to access files from other buckets. This is fixed in version 4.30. Update to the latest version to protect your data...
7.8
Prompty: Malicious Markdown Can Run Unwanted Code
CVE-2026-73299
A security issue in Prompty, a markdown file format for LLM prompts, allowed an attacker to run malicious code on the server. This could potentially lead to unauthorized actions or data breaches. To f...
10.0
Joomla Fabrik Extension - Unauthenticated Code Execution Risk
CVE-2026-67282
An attacker can execute code on your website without a password, which could lead to data theft or other malicious activities. This affects Joomla websites using Fabrik versions lower than 4.6.8. To p...
10.0
LXD Backup Data Tampering Enables Root File Access
DEBIAN-CVE-2026-66898
CVE-2026-66898
An attacker can manipulate file paths and overwrite files on the system by creating a malicious backup archive for LXD. This could lead to unauthorized access or data loss. Update LXD to the latest ve...
9.9
Red Hat Advanced Cluster Management: Privilege Escalation Risk
CVE-2026-72508
A vulnerability in Red Hat Advanced Cluster Management allows a tenant with limited access to gain high-level privileges and potentially execute arbitrary code on the cluster. This can happen when a t...
9.9
LXD: Moving instances bypasses project security restrictions
DEBIAN-CVE-2026-63300
CVE-2026-63300
An attacker with permission to create instances in one project can move a specially crafted instance to another project, potentially executing arbitrary commands. This can happen if an instance is cre...
9.9
LXD NVIDIA Configuration Data Injection Risk
DEBIAN-CVE-2026-63298
CVE-2026-63298
An attacker with LXD access can inject malicious configuration, potentially allowing them to execute code on the host system. This risk exists when an authenticated user configures an NVIDIA instance ...
9.9
LXD Security: Unauthorized Instance Copy in Restricted Projects
DEBIAN-CVE-2026-63297
CVE-2026-63297
An attacker with valid access can copy instances into projects with tighter security controls. This could allow them to gain more privileges or access sensitive data. To mitigate this risk, ensure all...
9.9
LXD: Unauthorized Instance Migration into Restricted Projects
DEBIAN-CVE-2026-63296
CVE-2026-63296
An attacker can move instances into projects with restricted settings, bypassing security controls. This is a concern because it allows unauthorized access to sensitive data or systems. To mitigate th...
9.9
LXD Image Backup Vulnerability: Root Access via Malicious Archive
DEBIAN-CVE-2026-63294
CVE-2026-63294
An attacker can exploit a weakness in LXD's image import process to gain root access on a system. This happens when a malicious image archive contains a specially crafted backup file. To protect your ...
9.9
LXD: Untrusted Image Can Read/Write Host Files as Root
CVE-2026-63293
DEBIAN-CVE-2026-63293
LXD, a Linux container manager, has a vulnerability that allows an attacker to access and modify files on the host system by importing a specially crafted image. This could lead to unauthorized data a...
9.9
ScadaLTS allows any user to run system commands
CVE-2026-19656
A flaw in ScadaLTS 2.7.8.1 allows any authenticated user to execute system commands on the host, potentially leading to a complete system compromise. This affects any system running ScadaLTS 2.7.8.1. ...
9.9
LXD Cross-Project Migration Bypasses Security Restrictions
CVE-2026-62420
DEBIAN-CVE-2026-62420
An attacker with access to LXD can move instances into restricted projects without permission. This allows them to introduce unwanted configurations into those projects. To protect your systems, ensur...
9.9
Multicluster Engine: Privilege Escalation via Job Injection
CVE-2026-73268
An attacker with specific permissions can inject malicious code into a critical system component, potentially gaining elevated privileges and accessing sensitive information. This vulnerability affect...
9.9
OpenShift: Cluster-wide secrets access via tenant-controllable trigger
CVE-2026-73269
An attacker in a specific namespace can create a resource that grants them access to sensitive cluster-wide secrets and elevated permissions. This is a significant risk because it allows the attacker ...
9.9
IBM i Remote Code Execution Vulnerability
CVE-2026-16860
IBM i versions 7.6, 7.5, 7.4, and 7.3 have a security weakness that could allow an attacker to take control of your system remotely. This means an attacker could potentially access and manipulate sens...
9.9
Prowler: Unauthorized Access via Misconfigured Kubernetes Settings
CVE-2026-73263
A security issue in Prowler's Kubernetes provider allows an attacker to execute commands on the system if they have access to a misconfigured Kubernetes configuration file. This could potentially allo...
9.9
OpenShift Multicloud Integrations allows arbitrary code execution
CVE-2026-72526
A vulnerability in OpenShift's multicloud integrations component allows an attacker to execute arbitrary code on managed clusters. This can happen if a tenant with permission to create applications on...
9.9
IBM Db2 Buffer Overflow Risk in Data Import
CVE-2026-10534
IBM Db2 versions 11.5 and 12.1 have a security issue that allows an attacker to potentially cause a system crash or execute malicious code when importing data. This is a serious risk because an attack...
9.8
MongoDB BI Connector ODBC driver may cause data corruption or crashes
CVE-2026-19001
A security flaw in the MongoDB BI Connector ODBC driver could cause the program using it to crash or behave unexpectedly. This is because the driver doesn't handle very long names properly, which can ...
9.5
IBM Verify and Security Verify Access: Weak Cryptography
CVE-2026-17616
IBM Verify Identity Access and IBM Security Verify Access may not properly verify user input, potentially allowing attackers to bypass security checks. This affects users who rely on these systems for...
9.8
IBM Db2 allows attackers to gain elevated access
CVE-2026-10543
Certain versions of IBM Db2 are vulnerable to a security weakness that could allow an attacker to gain more access to the database than they should have. This matters because it could allow unauthoriz...
9.8
WolfStack < 25.9.2: Unauthorized Access to Docker and LXC Containers
CVE-2026-73519
WolfStack versions before 25.9.2 have a security flaw that allows unauthorized access to Docker and LXC containers. This means that an attacker could potentially gain access to sensitive information a...
9.3
VinceTrack Attachment Leaks Coordinator Material
CVE-2026-18749
The VinceTrack software has a flaw that allows unauthorized access to sensitive case information. This can happen when a coordinator uploads a case artefact that is not shared, but is still accessible...
9.8