Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 25 August 2026
RSS1233 vulnerabilities published on 25 August 2026
Severity:
TOTOLINK N600R router can be remotely compromised via hostname
CVE-2026-79911
The router’s web interface has a flaw that lets an attacker send a specially crafted hostname and cause the system to overflow its memory. This can be triggered from anywhere on the internet, potentia...
9.3
Adobe Campaign Classic can run unwanted code
CVE-2026-76197
Adobe Campaign Classic lets an attacker send specially crafted data that causes the system to run any command it wants, without needing a user to click anything. This can lead to the attacker taking c...
10.0
Adobe Campaign Classic can run unauthorized code
CVE-2026-76195
Adobe Campaign Classic may allow an attacker to run any program on the server without needing a user to click anything. This could let the attacker take control of the system or access data. Apply the...
10.0
Adobe Campaign Classic lets attackers run code on your server
CVE-2026-76193
Adobe Campaign Classic can be tricked into contacting internal systems and running whatever code an attacker supplies. This can happen without any user clicking anything, giving the attacker control o...
10.0
miniOrange SAML login lets attackers log in as any user
CVE-2026-77998
The miniOrange SAML Single Sign-On extensions for Joomla (versions before 11.0.2 and 6.4) do not correctly check the digital signature on login messages. Because of this, a stranger can send a special...
10.0
NVIDIA OpenShell for Linux can let attackers break out of its sandbox
CVE-2026-65093
The OpenShell component on Linux systems from NVIDIA has a weakness that could let a malicious user escape the protective sandbox it runs in. If exploited, they could run their own code, gain higher s...
9.9
NVIDIA OpenShell for Linux may let attackers run code
CVE-2026-65083
The NVIDIA OpenShell component used on Linux systems has a weakness in the part that controls which actions are allowed. This flaw could allow a malicious user to run their own code, gain higher acces...
9.9
Unauthenticated Code Execution via Erlang Term Deserialization in Elixir gRPC
UBUNTU-CVE-2026-48853
CVE-2026-48853
EEF-CVE-2026-48853
GHSA-grp7-v8xh-rj7h
Elixir gRPC versions 0.4.0 to 1.0.0 are vulnerable to unauthenticated code execution and denial of service attacks. An attacker can crash the server by exhausting its atom table or execute arbitrary c...
9.9
ClipBucket V5 installer lets anyone run commands on server
CVE-2026-80138
The web installer in ClipBucket version 5 does not check a setting called php_cli_filepath before using it in a command line. This lets anyone on the internet send a specially crafted request to the i...
9.2
Drupal Commerce Elavon may expose payment data
CVE-2026-16641
The Drupal Commerce Elavon add‑on can allow attackers to view or alter payment information. This puts customer credit‑card details at risk and could affect any site using the add‑on. Install the lates...
9.8
Apache Tomcat can bypass certificate checks
DEBIAN-CVE-2026-65637
CVE-2026-65637
BIT-tomcat-2026-65637
UBUNTU-CVE-2026-65637
Certain 9.x, 10.x, and 11.x versions of Apache Tomcat have an incomplete fix that can let an attacker bypass the check that confirms the server is talking to the correct website. This could allow a ma...
9.8
Chrome for Android allows co-installed app to bypass site restrictions
CVE-2026-79152
DEBIAN-CVE-2026-79152
If you use Google Chrome on Android versions before 152.0.7977.65, a malicious app installed on the same device could trick Chrome into ignoring its normal website security rules. This could let the a...
9.8
Google Chrome (pre‑152) can be tricked to bypass controls
CVE-2026-79090
DEBIAN-CVE-2026-79090
Older versions of Google Chrome may let a specially crafted webpage bypass the normal security checks that keep users from accessing restricted parts of the system. If someone convinces a user to open...
9.8
NVIDIA NemoClaw Linux remote helper can be bypassed
CVE-2026-65098
The remote-access component of NVIDIA NemoClaw on Linux can be tricked into weak authentication, allowing an attacker to run code, view sensitive information, or alter data. This risk affects any syst...
9.8
NVIDIA NemoClaw Linux may accept fake certificates
CVE-2026-65084
The Linux version of NVIDIA NemoClaw can be tricked during installation into trusting invalid security certificates. This could let an attacker see sensitive information, alter data, run unauthorized ...
9.8
NVIDIA NemoClaw Linux installer can run malicious code
CVE-2026-65081
The installer for NVIDIA NemoClaw on Linux may allow an attacker to insert and run their own code. If exploited, this could let the attacker take control of the system, modify or steal data, and cause...
9.8
Tongweb 7.0.24 lets attackers run code remotely
CVE-2026-51368
The Tongweb server version 7.0.24 has a flaw in its web console that can be triggered by a specially crafted request, allowing an outside attacker to run any program on the server. This could let the ...
9.8
DB-GPT 0.8.0 lets unauthenticated users write files anywhere
CVE-2026-80104
The DB‑GPT version 0.8.0 web interface lets anyone upload a file and choose the file name, but it does not verify that the name stays inside the designated upload folder. Because the check is missing,...
9.3
Chainlit allows remote code execution when MCP enabled
CVE-2026-45018
GHSA-w3fx-mc44-mf6j
If your Chainlit setup turns on the MCP feature, anyone who can reach the /mcp endpoint can run any command on your server. This happens because the system only checks the program name, not its argume...
9.8
Alluxio allows attackers to impersonate users and access data
CVE-2026-79787
Alluxio’s built‑in gateway for cloud storage does not check that incoming requests really come from an authorized source when left in its default setup. This lets anyone pretend to be any user, includ...
9.8
Kaltura HTML5 player lets remote attacker run code
CVE-2026-19912
The Kaltura HTML5 video player (mwEmbed / html5lib) in versions up to 2.45 and 2.103 can be tricked by anyone on the internet to run code on your server. This lets an attacker place files in web-acces...
9.8
NLTK library can run malicious code via unsafe Java options
GHSA-m4rf-3fr8-xwx3
DEBIAN-CVE-2026-79675
UBUNTU-CVE-2026-79675
CVE-2026-79675
Versions of the NLTK Python library before the latest release let attackers add dangerous Java settings when calling its java() function. This can let an attacker run arbitrary code on the system. Upd...
9.9
Nokogiri can crash or be hijacked by crafted XML
CVE-2025-71407
The Ruby library Nokogiri, used to read and process XML data, can be forced to crash or run unwanted code when it handles specially crafted XML definitions from untrusted sources. This could let an at...
9.3
qwed-mcp lets attackers run commands via math input
CVE-2026-55546
GHSA-mw6r-2hvm-4rp2
The qwed-mcp tool (version 0.2.0) processes math expressions without checking them, letting a malicious user insert code that the system will execute. This can give an attacker full control over the s...
9.8
Nokogiri update fixes XML parsing vulnerability in libxml2
CVE-2024-58378
GHSA-xc9x-jj77-9p9j
A security update for Nokogiri fixes a vulnerability that could be exploited by malicious XML documents. This affects users of the packaged version of Nokogiri, not those who use system libraries. To ...
9.9