Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 14 August 2026

RSS

837 vulnerabilities published on 14 August 2026

Severity:
MindsDB Minds Platform v26.1.0: Unauthenticated Code Execution
CVE-2026-73678
An attacker can execute any system command without a password, potentially stealing sensitive data or taking control of the system. This is a serious issue because it affects the security of sensitive...
10.0
Haiwell IoT Cloud HMI Gateway allows attackers to run commands
CVE-2026-19188
An attacker can exploit a weakness in the Haiwell IoT Cloud HMI Gateway, potentially allowing them to access sensitive areas of the system. This could lead to unauthorized changes or data theft. Updat...
10.0
SiYuan can let attackers read or change notes
GHSA-p8cp-78hp-wmq8
Versions of the SiYuan note‑taking software up to 3.7.2 contain a flaw where specially crafted text can manipulate the program’s database commands. An attacker who can enter a search term or create a ...
9.9
SiYuan can let attackers read and modify notebooks
GHSA-p8cp-78hp-wmq8
Versions of the SiYuan note‑taking tool up to 3.7.2 let a user enter specially crafted text that can trick the system into running its own commands. This could allow someone to view or change any note...
9.1
IBM Db2 Mirror for i allows arbitrary CL command execution
CVE-2026-17186
IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 have a security issue. A hacker could potentially take control of your system if they exploit this flaw. Update to the latest version to fix the issue.
9.9
Adobe Security Center Command Execution Risk
CVE-2026-19682
Adobe Security Center is at risk of attackers executing unauthorized commands on its system. This could lead to sensitive data exposure or system compromise. Adobe should be notified to patch the issu...
9.4
Adobe Security Center Command Injection Risk
CVE-2026-19681
Adobe Security Center has a vulnerability that allows attackers to execute arbitrary commands on the system if a malicious file is uploaded. This could potentially lead to system compromise or data th...
9.4
Tenable Security Center Report Generation Code Execution Risk
CVE-2026-19626
A security flaw in Tenable Security Center's report generation feature could allow an authorized user to execute malicious code on the system. This could lead to unauthorized access or data compromise...
9.4
IBM Db2 Mirror for i: Unauthorized Access to Sensitive Data
CVE-2026-17182
IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 have a security weakness that could allow an attacker to access sensitive information without a password. This could happen if an attacker knows the rig...
9.8
IBM Db2 Mirror for i: Remote Code Execution via Malicious File
CVE-2026-17184
IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 are affected by a vulnerability that could allow an attacker to execute malicious code on your system. This is a serious risk because an attacker could ...
9.8
mcp-memory-service: Unauthenticated Access to Document API Endpoints
GHSA-84hp-mqvj-3p8h CVE-2026-50027
An attacker can upload, read, or delete sensitive data without a password. This is a security risk because it allows unauthorized access to user memories. To fix this, update the mcp-memory-service to...
9.8
Metacat's data repository software can be hacked through SQL attack
CVE-2026-48528
Metacat's data sharing software, used by researchers, has a security weakness that allows hackers to access and manipulate sensitive data without a password. This puts protected information at risk. T...
9.8
Emlog Unauthenticated Reinstallation via install.php
CVE-2026-73849
Emlog website builders are at risk of having their configuration files overwritten and new administrator accounts created if an attacker submits malicious data to the install.php page. This is a conce...
9.8
Wishlist Member <= 3.34.1: Unauthenticated Account Takeover via 'mergewith' Parameter
CVE-2026-12949
A security flaw in Wishlist Member plugin for WordPress versions up to 3.34.1 allows attackers to take over any WordPress account, including administrator accounts, by manipulating a specific paramete...
9.8
OpenSSH 10.4 or earlier: Host Key Change Security Risk
JLSEC-2026-1326
Older versions of OpenSSH may allow a server to bypass security checks when its host key is changed. This is a security risk for users who connect to servers with OpenSSH. To stay secure, update to Op...
9.4
Prospero Flow CRM employee onboarding uses insecure default password
CVE-2026-19871
Prospero Flow CRM's employee onboarding process in older versions uses a default password for all employees, making it easy for unauthorized users to access employee accounts if they know the email ad...
9.3
Joomla icagenda.com Extension Allows Unauthorized Access
CVE-2026-67365
The Joomla icagenda.com extension has a security flaw that allows attackers to execute unauthorized database queries without logging in. This can lead to sensitive data exposure and unauthorized actio...
9.2
Google QUIC and HTTP/3 allow man-in-the-middle attacks
GHSA-2r8v-p65x-3663 CVE-2026-49457
A security flaw in Google's QUIC protocol allows an attacker to pretend to be a trusted server, potentially stealing sensitive information. This affects QUIC and HTTP/3 clients, but not when using ses...
9.1
Red Hat OpenStack Platform 16.2 - Unauthenticated API Access
RHSA-2026:54757
Red Hat OpenStack Platform 16.2 has an issue with its API that allows unauthorized users to access certain features. This could allow an attacker to perform actions without proper authorization, poten...
9.1
Red Hat Hardened Images: Unvalidated Input Risk
RHSA-2026:54549
Red Hat Hardened Images are affected by a security risk where unvalidated input can lead to arbitrary code execution. This affects the security of systems using these images. Users should apply the la...
9.1
Python Pillow library can run malicious code
RHSA-2026:54528
The Pillow image‑processing library used in many Python applications has a flaw that could let an attacker execute unwanted code when processing crafted image files. This could affect any system that ...
9.1
Semaphore UI: Untrusted Git URL Executes Server Commands
CVE-2026-73294 CVE-2026-73682 GHSA-xp7j-h7jc-4w8p
Semaphore UI's web interface for managing DevOps tools is affected. An attacker can execute arbitrary server commands by manipulating a project's git URL. Update Semaphore UI to version 2.18.17 or 2.1...
8.7
Semaphore UI: Malicious Git Commands Can Be Run
CVE-2026-73294 CVE-2026-73682
Semaphore UI's web interface for managing DevOps tools has a security issue that allows a malicious user to run arbitrary system commands on the server. This could potentially allow an attacker to acc...
9.4
IBM Db2 Mirror for i: Unauthorized Access via User Input
CVE-2026-16879
IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 have a security issue. An attacker with remote access and valid credentials could exploit this to gain unauthorized access to the system. Update to the ...
8.8
Cockpit CMS Authenticated Command Injection via Video File
CVE-2026-73680
Cockpit CMS versions 2.14.0 and earlier have a security flaw in their video processing feature. An attacker with permission to upload files can exploit this flaw to execute unauthorized system command...
8.7