Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 19 August 2026

RSS

1509 vulnerabilities published on 19 August 2026

Severity:
Ozols Grupa OZOLS Windows Code Download Risk
CVE-2026-22306
A security issue in Ozols Grupa OZOLS affects Windows users. The issue allows malicious code to be downloaded and executed without being checked for authenticity. This could lead to sensitive informat...
10.0
Cisco Crosswork: File System Control Weakness Fixed
CVE-2026-20358
Cisco Crosswork has released a security update to fix internal weaknesses in its file system control. This update addresses potential security risks that could allow unauthorized access to the system....
10.0
Cisco Crosswork Missing Authentication for Critical Functions
CVE-2026-20357
Cisco Crosswork's security review found a way to bypass authentication for critical functions. This could allow unauthorized access to sensitive data or systems. To fix this, update to the latest hard...
10.0
Cisco Secure Workload: Unauthorized Access Risk
CVE-2026-20315
A security update for Cisco Secure Workload has been released to fix weaknesses that could allow unauthorized access to sensitive data. This update is a proactive measure to improve security and preve...
10.0
Cisco Crosswork: SQL Command Injection Risk
CVE-2026-20030
Cisco Crosswork software may be vulnerable to SQL command injection attacks, which can allow hackers to access sensitive data or take control of the system. This vulnerability was discovered internall...
10.0
Cisco Secure Workload Software - Authentication Weakness
CVE-2026-20317
The Cisco Secure Workload software has a weakness in its authentication system. This means that an attacker could potentially gain unauthorized access to the system. Cisco has released a software upda...
10.0
J-BusinessDirectory Joomla Extension: Unsecured File Upload/Deletion
CVE-2026-75949
An unsecured Joomla extension called J-BusinessDirectory allows attackers to upload or delete any file on the server. This is a serious issue because it could allow an attacker to harm the website or ...
10.0
Joomla Zoo Extension Allows Unsecured File Uploads
CVE-2026-74803
The Zoo extension for Joomla, a popular content management system, has a security issue that allows an attacker to upload any type of file without needing a password. This can be used to spread malwar...
10.0
Joomla Balbooa Forms < 2.4.3.2 - Unauthenticated PHP Code Injection
CVE-2026-67364
A security issue affects Joomla's Balbooa Forms extension. An attacker can inject malicious PHP code without needing a password, potentially leading to data theft and system compromise. To stay safe, ...
10.0
W3 Total Cache < 2.10.5 - Attackers Can Overwrite Important Files
CVE-2026-18051
An outdated version of the W3 Total Cache plugin for WordPress allows attackers to write files into any directory on the server, including the site's .htaccess files. This can break the site and remov...
10.0
Comfast CF-N1-S: Remote Code Execution via Malformed Image
CVE-2026-76008
A security issue has been discovered in the Comfast CF-N1-S 2.6.0.1. This affects the way it handles certain image files. An attacker can potentially send a malicious image to the device, allowing the...
10.0
TRENDnet TEW-755AP WAN CGI Remote Overflow Risk
CVE-2026-76590
The TRENDnet TEW-755AP's WAN CGI feature has a security flaw that could allow hackers to remotely crash the device. This could happen if an attacker sends a specific type of data to the device. To pro...
8.6
TRENDnet TEW-755AP Router: Unsecured Remote Access
CVE-2026-76589
A security flaw in the TRENDnet TEW-755AP router can be exploited remotely, potentially allowing unauthorized access. This issue affects the router's functionality and poses a risk to users. Users are...
8.6
TRENDnet TV-IP751WIC: Unsecured Time Setting Allows Remote Attack
CVE-2026-76584
An outdated version of the TRENDnet TV-IP751WIC internet camera has a security issue in its time setting feature. This flaw can be exploited remotely, potentially allowing attackers to access the came...
8.6
Etherpad: Non-admin users can access admin features
CVE-2026-55089 GHSA-qfmh-fph3-mw8q
Etherpad's authorization system had a bug that allowed non-admin users to access sensitive features. This bug was fixed in version 3.1.0. If you're using an earlier version of Etherpad, we recommend u...
9.9
Search-v2-operator has excessive cluster administrator permissions
CVE-2026-70496
The Search-v2-operator has too many permissions, which could allow an attacker to take control of the cluster. This is a concern because the operator is meant to manage search functionality, not have ...
9.9
FreeRDP Remote Desktop Protocol Client Heap Corruption
DEBIAN-CVE-2026-63633 UBUNTU-CVE-2026-63633 CVE-2026-63633 GHSA-72j9-356v-88xq
FreeRDP, a free implementation of the Remote Desktop Protocol, has a bug that can cause a client to crash or run malicious code. This bug affects clients built with certain settings and connecting to ...
9.9
Cisco Secure Workload Improper Neutralization Vulnerability
CVE-2026-20231
Cisco Secure Workload software has a security issue where malicious input is not properly handled. This could allow an attacker to execute unintended code. Cisco has released a software update to addr...
9.9
Cisco Crosswork: Insufficiently Protected Credentials
CVE-2026-20359
Cisco Crosswork users should be aware of a security update that addresses vulnerabilities related to password protection. This update is a proactive measure to strengthen the security of the software....
9.9
IBM AIX and PowerVM VIOS Command Injection Risk
CVE-2026-16816
IBM AIX and PowerVM VIOS have a security weakness that allows a malicious user to execute unauthorized commands on the system. This could potentially lead to unauthorized access or data tampering. IBM...
9.9
IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 NIM Command Injection
CVE-2026-15068
A remote attacker can run unauthorized commands on affected systems. This is a serious issue because it allows an attacker to take control of the system. Affected users should update to the latest ver...
9.9
stigmem-node: Anonymous access risk when auth is disabled outside loopback
GHSA-fp6w-8wpg-74g5 CVE-2026-76243
Operators who intentionally disabled authentication in stigmem-node may inadvertently grant broad access to anonymous users if the node is exposed outside a local development environment. To avoid thi...
9.9
UTT HiPER 1250GW allows remote code execution
CVE-2026-76004
A security flaw in the UTT HiPER 1250GW's web interface allows attackers to remotely execute malicious code. This could lead to unauthorized access or disruption of the device. Update the device to th...
8.6
UTT HiPER 1200GW allows remote code execution through input manipulation.
CVE-2026-76003
A security issue exists in UTT HiPER 1200GW, specifically in the way it handles certain input. This can allow an attacker to remotely execute malicious code on the device. Users should update to a fix...
8.6
TRENDnet TEW-823DRU: Remote Password Exposure
CVE-2026-75976
A security issue has been found in the TRENDnet TEW-823DRU router's password handling. This could allow an attacker to access the router's settings remotely. To stay secure, update the router's firmwa...
8.6