Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 17 August 2026
RSS928 vulnerabilities published on 17 August 2026
Severity:
vm2: NodeVM exposes sensitive host data to unauthorized actors
GHSA-m5w8-4gq2-6f8x
A vulnerability in vm2 allows an attacker to access sensitive host data, including user information and network topology. This can lead to unauthorized access and hijacking of the host's DNS and netwo...
10.0
vm2: NodeVM exposes sensitive host data and hijacks host DNS
GHSA-m5w8-4gq2-6f8x
A vulnerability in the NodeVM module allows an attacker to access sensitive host data and hijack the host's DNS settings, potentially leading to unauthorized access and data corruption. To mitigate th...
10.0
Joomla Extension - regularlabs.com - Unauthenticated Code Execution
CVE-2026-74253
The Regular Labs Sourcerer extension in Joomla doesn't properly check the source of code it processes. This means an attacker could inject malicious code into a Joomla site, potentially allowing them ...
10.0
Wavlink WN531P3/WN535M1: Remote Code Execution via Cookie Overflow
CVE-2026-74843
The Export Pingortrace CGI feature in Wavlink WN531P3 and WN535M1 devices is vulnerable to a remote attack. An attacker can exploit this vulnerability by sending a specially crafted cookie, potentiall...
9.3
Terraform MCP Server Credentials Can Be Shared Across Users
CVE-2026-16498
BIT-consul-2026-16498
The Terraform MCP Server before version 1.1.0 allows one user's credentials to be used by other users. This means that if one user's credentials are compromised, an attacker could use them to access a...
10.0
Consul MCP Server Exposes Client Credentials in Stateless Mode
CVE-2026-16326
BIT-consul-2026-16326
A security issue in Consul MCP Server versions 0.1.0 to 0.1.3 allows one client's login credentials to be used by other clients. This means unauthorized access to your Consul data is possible. Update ...
10.0
EFM ipTIME A3004T Session Validation: Improper Authentication Risk
CVE-2026-19977
A security issue exists in EFM ipTIME A3004T 14.19.0 that allows unauthorized access. This could happen if an attacker manipulates the session validation process. We recommend checking with the vendor...
9.3
ERPNext: Attackers can run code on your server
CVE-2026-65974
GHSA-w996-r7v3-87wr
ERPNext users with limited access may be able to run unauthorized code on your server. This could allow hackers to access sensitive data or take control of your system. Update to the latest version of...
9.9
Managedcluster-import-controller: Malicious CSR Can Grant Hub Cluster Access
CVE-2026-66795
A security flaw in the managedcluster-import-controller allows a malicious service account on a connected cluster to submit a fake request for a security certificate. If exploited, this could grant th...
9.9
OpenShift: Unauthorized access to cluster resources
CVE-2026-66792
A vulnerability in OpenShift allows a user with access to a managed cluster to create a Subscription that gives them elevated permissions. This could lead to unauthorized access and control over clust...
9.9
VM2 Sandbox Escape via Missing Error.cause Sanitization
GHSA-m283-3h24-438v
CVE-2026-47686
A vulnerability in VM2 versions up to 3.11.3 allows malicious code to escape the sandbox and execute arbitrary commands on the host system. This is because VM2 does not properly sanitize the Error.cau...
9.9
Mahara Text Block Vulnerability: Unintended Content Recall
CVE-2026-42164
Older versions of Mahara allow an attacker to access content from another user's Text block by crafting a specific request. This could potentially allow an attacker to view sensitive information. To f...
9.8
PbootCMS v.3.2.15 allows code execution
CVE-2026-67960
An attacker can execute malicious code on your PbootCMS website if they find a vulnerability in it. This is a serious risk because it could allow them to steal data, install malware, or take control o...
9.8
S2OPC Server Code Execution through Malicious OPC Requests
CVE-2026-67868
A vulnerability in S2OPC 1.7.3 allows an attacker to send malicious requests to the server, potentially executing unauthorized code. This could lead to unauthorized access or data corruption. We recom...
9.8
Qcms v.6.0.6: Remote Code Execution via SQL Injection
CVE-2026-67854
A security weakness in Qcms v.6.0.6 allows an attacker to run malicious code on the system, potentially leading to data theft or system compromise. To protect your system, update Qcms to the latest ve...
9.8
Mahara LTI Access Risk - Unauthorized Account Access
CVE-2026-42163
Mahara versions 25.04.5 and earlier, and 26.04.0, have a security issue that allows unauthorized access to internal accounts. This is a concern for institutions using Mahara for learning and collabora...
9.8
MemOS Authentication Bypass: Unauthenticated Access to Admin Endpoints
CVE-2026-75110
MemOS, a memory operating system for AI agents, has a security issue that allows an attacker to access sensitive admin endpoints without authentication. This could lead to unauthorized actions such as...
9.3
Tenda W20E Router Allows Malicious Code Execution
CVE-2026-67967
A security flaw in Tenda W20E routers makes them vulnerable to unauthorized code execution. This could allow an attacker to take control of the router, potentially disrupting internet access for users...
9.8
Tenda W20E Telnet Service Left Unsecured
CVE-2026-67966
The Tenda W20E wireless router has a security issue where an attacker can remotely access the router without a password and gain full control. This can allow an attacker to change settings, access sen...
9.8
Tneda W20E Remote Code Execution Vulnerability
CVE-2026-67965
Tneda W20E version 16.01.0.6 is at risk of being exploited by hackers who can execute malicious code remotely, potentially leading to unauthorized access or data theft. This vulnerability affects the ...
9.8
JeecgBoot AI Chat Module Code Execution Vulnerability
CVE-2026-67926
A security issue in JeecgBoot v.3.9.2 allows an attacker to run unauthorized code on your server. This could lead to data theft, system crashes, or other malicious actions. We recommend updating to th...
9.8
zuraCast Backup Restore SQL Injection Risk
CVE-2026-67917
Old zuraCast versions have a security risk in their backup restore feature. If not updated, an attacker could gain more access to your system. Update to a safe version of zuraCast to fix this issue.
9.8
SteelSeries GG for macOS can run unauthorized code
CVE-2026-39255
The SteelSeries GG app for macOS has a security issue that allows a hacker to run their own code on your computer. This could potentially let the hacker steal your personal data or take control of you...
9.8
SteelSeries GG (macOS) v.107.0.0 allows remote code execution
CVE-2026-39254
A vulnerability in SteelSeries GG for macOS could allow an attacker to run malicious code on a user's computer without their permission. This could happen if a user opens a malicious file or visits a ...
9.8
vm2: Malicious Code Escapes Sandbox on Host System
GHSA-cfcw-xp6x-25gj
CVE-2026-47698
The vm2 sandboxing system has a security weakness that allows attackers to write code that can break free from the sandbox and execute malicious commands on the host system. This means that if an atta...
9.8