Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 23 August 2026
RSS79 vulnerabilities published on 23 August 2026
Severity:
StackGres lets database user gain admin rights
CVE-2026-78155
The StackGres management component can be tricked by a regular database user into obtaining full administrator access. This means a low‑level tenant could control the entire system and access data bey...
9.9
Perl DBD::Pg 3.21.0 may write beyond memory when handling special numbers
CVE-2026-78183
GHSA-785p-fw3v-r822
UBUNTU-CVE-2026-78183
If your Perl applications use DBD::Pg version 3.21.0 to talk to PostgreSQL, certain special numeric values like Infinity or NaN can cause the software to write a few extra bytes into memory. This memo...
9.8
JustHTML: Untrusted Input Can Become Raw HTML in Markdown Output
GHSA-3rcm-vjrc-p45j
JustHTML's Markdown conversion can leave untrusted input unchanged, potentially executing malicious scripts. This is a concern when allowing user-generated content. To mitigate, ensure you're using th...
9.3
JustHTML Can Produce Malicious HTML Output
CVE-2026-8445
GHSA-3rcm-vjrc-p45j
JustHTML can create malicious HTML when converting certain text inputs to Markdown. This can allow an attacker to inject malicious code into your website. To fix this, you should update to the latest ...
9.9
Justhtml 1.16.0 fixes security risks in HTML sanitization
GHSA-4p64-v8f5-r2gx
Justhtml versions 1.15.0 and earlier have security weaknesses in how they handle certain HTML inputs. This can lead to malicious code being executed when sanitizing HTML. To fix this, update to Justht...
9.3
Justhtml Sanitization Flaw Affects Programmatic DOM Input
CVE-2026-7808
GHSA-4p64-v8f5-r2gx
The justhtml library versions 1.15.0 and earlier contain multiple security flaws that can allow malicious code to bypass sanitization. These flaws can occur when using custom policies or programmatic ...
9.9
JustHTML versions 1.15.0 fixes security flaws in URL sanitization and HTML generation
CVE-2026-5388
GHSA-c9vm-hv86-f23r
JustHTML versions prior to 1.15.0 have security flaws in URL sanitization and HTML generation. These flaws could allow malicious code to be injected into websites, potentially allowing attackers to st...
9.9
JustHTML Sanitization Flaw Allows Malicious Code Execution
GHSA-c9vm-hv86-f23r
JustHTML versions 1.14.0 and earlier have a security issue that can allow malicious code to be executed on your website. This is because the software doesn't properly sanitize user input, which means ...
9.3
RestrictMate plugin lets anyone create admin account
CVE-2026-13598
The RestrictMate add‑on for WordPress (versions before 1.3.0) does not check the role chosen when a new user signs up. This lets anyone on the internet register and become an administrator, giving the...
9.8
GitLab could let logged-in users run code remotely
CVE-2026-10053
All GitLab Community and Enterprise editions released before the latest patches are vulnerable. A signed-in user could exploit the package storage feature to make the server run their own commands, po...
8.8
rootio-tiff: Untrusted Tiff Image Can Crash Root Server
ROOT-OS-DEBIAN-11-CVE-2025-8177
ROOT-OS-DEBIAN-12-CVE-2025-8177
CVE-2025-8177
DEBIAN-CVE-2025-8177
The rootio-tiff package in Root:Debian:11 has a bug that can be exploited by an attacker to crash the server. This is a serious issue because it can cause the server to become unresponsive, potentiall...
6.9
CHIRP radio program can be tricked to run code
CVE-2026-78136
Versions of the CHIRP radio utility released before a recent update will execute code hidden in specially crafted CSV files. If a user opens such a file, an attacker could run unwanted programs or ste...
7.8
JustHTML may crash when parsing deeply nested HTML
GHSA-892m-gcq8-2468
The JustHTML library (versions up to 1.9.1) can stop working if it processes HTML that contains many layers of nested tags. This can cause the application to fail or stop responding, affecting any ser...
8.7
JustHTML Denial of Service via Recursion
GHSA-v7cf-c9rm-wm3j
JustHTML versions 1.9.1 and earlier can crash or fail when processing deeply nested HTML input. This can cause a denial of service if not handled properly. Update to version 1.9.2 or later to fix this...
8.7
JustHTML: Deeply Nested HTML Triggers Crash
CVE-2026-9769
GHSA-v7cf-c9rm-wm3j
JustHTML versions 1.0 through 1.9.1 can crash or freeze if it's given very deeply nested HTML input. This could cause a service to become unresponsive or stop working. To fix, update to version 1.9.2 ...
8.7
justhtml Denial-of-Service Vulnerability in CSS and Linkification
CVE-2026-4671
GHSA-r8cj-3554-33mr
justhtml versions prior to 1.18.0 are vulnerable to denial-of-service attacks when processing CSS selectors and links. This could cause a website to consume excessive CPU or memory, making it unavaila...
8.3
justhtml Denial-of-Service Vulnerability Fixed
GHSA-r8cj-3554-33mr
justhtml versions before 1.18.0 may consume excessive system resources if given certain types of input, potentially causing performance issues. This issue affects applications that use justhtml to pro...
8.7
Rootio-tiff: Malicious TIFF Files Can Crash Root Devices
ROOT-OS-DEBIAN-11-CVE-2023-52355
ROOT-OS-DEBIAN-12-CVE-2023-52355
UBUNTU-CVE-2023-52355
CVE-2023-52355
The rootio-tiff package, used on Root devices, had a bug that could cause a device to crash if it processed a specially crafted TIFF file. This is now fixed in updated versions of the package. Update ...
7.5
Tenda CH22 router lets remote attackers run commands
CVE-2026-78141
The Tenda CH22 router’s web interface contains a flaw that lets someone send specially crafted data to execute commands on the device. Because this can be done over the network, an attacker could gain...
2.1
Tenda CH22 router can run commands via file rename
CVE-2026-78063
The Tenda CH22 router lets an attacker change a file name in a way that runs unauthorized commands on the device. This can be done from outside the network, giving a remote user control of the router....
2.1
Llama.cpp RPC server can be tricked into remote code execution
CVE-2026-78147
DEBIAN-CVE-2026-78147
UBUNTU-CVE-2026-78147
The Llama.cpp software’s RPC server component can be fooled into processing specially crafted data, allowing an attacker to run code on the server from a distance. This happens because the server does...
8.4
Barangay Resident Profiling System can be tricked to expose data
CVE-2026-78143
The resident search page in the Barangay Resident Profiling Management System can be manipulated to run unauthorized database commands. This could let an attacker retrieve or alter resident informatio...
5.5
TaxHacker exposes JWT secret through hard‑coded credentials
CVE-2026-78062
The TaxHacker application (versions up to 0.8.2) stores its authentication secret in the code instead of a secure location. This makes it possible for an attacker to retrieve the secret and impersonat...
5.5
Brave Popup Builder can run injected scripts from URL links
CVE-2026-77115
The Brave Popup Builder plugin (versions before 0.8.6) inserts data from URL tracking parameters directly into the popup's code. An attacker could craft a link that makes the popup execute malicious J...
7.1
rootio-mariadb-10.5: Unauthorized access to database possible through root account
ROOT-OS-DEBIAN-11-CVE-2025-13699
CVE-2025-13699
ROOT-OS-DEBIAN-12-CVE-2025-13699
ROOT-OS-DEBIAN-13-CVE-2025-13699
A bug was found in the rootio-mariadb-10.5 package that could allow an attacker with a root account to access sensitive data in the database without permission. This could potentially lead to unauthor...
7.0