{"total":35540,"page":1,"count":50,"advisories":[{"id":"f8644fec-291d-4a0f-a655-571edc359e20","num":2158795,"source_id":"jvn","external_id":"https://jvn.jp/en/jp/JVN67155805/","title":"Android App \"Myna Point\" vulnerable to improper access restriction","summary":"Android App \"Myna Point\" provided by Digital Agency contains an improper access restriction vulnerability.","link":"https://jvn.jp/en/jp/JVN67155805/","severity":"unknown","cvss":null,"cves":["CVE-2026-73335"],"exploited":false,"has_exploit":false,"published_at":"2026-08-26T03:00:15+00:00","slug":"android-app-myna-point-vulnerable-to"},{"id":"582f14b9-1d68-46f2-907a-54d412b9c658","num":2158816,"source_id":"hkcert","external_id":"https://www.hkcert.org/security-bulletin/veeam-backup-and-replication-information-disclosure-vulnerability_20260826","title":"Veeam Backup & Replication Information Disclosure Vulnerability","summary":null,"link":"https://www.hkcert.org/security-bulletin/veeam-backup-and-replication-information-disclosure-vulnerability_20260826","severity":"unknown","cvss":null,"cves":["CVE-2026-58070"],"exploited":false,"has_exploit":false,"published_at":"2026-08-26T03:00:00+00:00","slug":"veeam-backup-replication-information"},{"id":"a7fa021a-9fc5-410e-b0c1-e46348980e04","num":2158815,"source_id":"hkcert","external_id":"https://www.hkcert.org/security-bulletin/google-chrome-multiple-vulnerabilities_20260826","title":"Google Chrome Multiple Vulnerabilities","summary":null,"link":"https://www.hkcert.org/security-bulletin/google-chrome-multiple-vulnerabilities_20260826","severity":"unknown","cvss":null,"cves":["CVE-2026-78891","CVE-2026-78892","CVE-2026-78893","CVE-2026-78894","CVE-2026-78895","CVE-2026-78896","CVE-2026-78897","CVE-2026-78898","CVE-2026-78899","CVE-2026-78900","CVE-2026-78901","CVE-2026-78903","CVE-2026-78904","CVE-2026-78905","CVE-2026-78906","CVE-2026-78907","CVE-2026-78908","CVE-2026-78909","CVE-2026-78910","CVE-2026-78911","CVE-2026-78912","CVE-2026-78913","CVE-2026-78914","CVE-2026-78915","CVE-2026-78934","CVE-2026-78935","CVE-2026-78936","CVE-2026-78937","CVE-2026-78938","CVE-2026-78939","CVE-2026-78940","CVE-2026-78941","CVE-2026-78942","CVE-2026-78943","CVE-2026-78944","CVE-2026-78945","CVE-2026-78946","CVE-2026-78947","CVE-2026-78948","CVE-2026-78949","CVE-2026-78950","CVE-2026-78951","CVE-2026-78952","CVE-2026-78953","CVE-2026-78954","CVE-2026-78955","CVE-2026-78956","CVE-2026-78957","CVE-2026-78958","CVE-2026-78959","CVE-2026-78960","CVE-2026-78961","CVE-2026-78962","CVE-2026-78963","CVE-2026-78964","CVE-2026-78965","CVE-2026-78966","CVE-2026-78967","CVE-2026-78968","CVE-2026-78969"],"exploited":false,"has_exploit":false,"published_at":"2026-08-26T03:00:00+00:00","slug":"google-chrome-multiple-vulnerabilities"},{"id":"9323c19b-72ad-4be2-ac3d-3e27ec97ff04","num":2158796,"source_id":"jvn","external_id":"https://jvn.jp/en/jp/JVN18496672/","title":"Multiple vulnerabilities in CorvusSKK","summary":"CorvusSKK provided by SASAKI Nobuyuki contains multiple vulnerabilities.","link":"https://jvn.jp/en/jp/JVN18496672/","severity":"unknown","cvss":null,"cves":["CVE-2026-76148","CVE-2026-76149"],"exploited":false,"has_exploit":false,"published_at":"2026-08-26T03:00:00+00:00","slug":"multiple-vulnerabilities-in-corvusskk"},{"id":"811e59eb-d50a-4f0b-9321-de5abb205178","num":2135541,"source_id":"jvn","external_id":"https://jvn.jp/en/vu/JVNVU95422936/","title":"FURUNO ELECTRIC FA-50 CLASS B AIS TRANSPONDER uses hard-coded credentials and misses authentication for additional configuration","summary":"FA-50 CLASS B AIS TRANSPONDER provided by FURUNO ELECTRIC CO., LTD. uses hard-coded credentials and misses authentication for additional configuration.","link":"https://jvn.jp/en/vu/JVNVU95422936/","severity":"unknown","cvss":null,"cves":["CVE-2026-59769","CVE-2026-67578"],"exploited":false,"has_exploit":false,"published_at":"2026-08-26T01:15:00+00:00","slug":"furuno-electric-fa-50-class-b-ais"},{"id":"87df16d5-ce25-44db-ba32-4fc5eb7e9180","num":2159182,"source_id":"ubuntu","external_id":"https://ubuntu.com/security/notices/USN-8659-4","title":"USN-8659-4: Linux kernel (Oracle) vulnerability","summary":"A security issue was discovered in the Linux kernel. An attacker could possibly use this to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch;","link":"https://ubuntu.com/security/notices/USN-8659-4","severity":"unknown","cvss":null,"cves":["CVE-2026-64531"],"exploited":false,"has_exploit":true,"published_at":"2026-08-26T00:14:56+00:00","slug":"usn-8659-4-linux-kernel-oracle"},{"id":"4483e9d4-2e18-44e3-beb4-88b121cc8948","num":2163810,"source_id":"nvd","external_id":"CVE-2026-80138","title":"CVE-2026-80138: ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a craft","summary":"ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath value to execute arbitrary commands as the web server user.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-80138","severity":"critical","cvss":9.8,"cves":["CVE-2026-80138"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:17:59.86+00:00","slug":"cve-2026-80138-clipbucket-v5-s-web-installer-fails-to"},{"id":"9ec01ea8-159c-4109-acd4-210c3021455a","num":2163809,"source_id":"nvd","external_id":"CVE-2026-79912","title":"CVE-2026-79912: A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulati","summary":"A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The attack can be initiated remotely. The exploit is now public and may be used.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-79912","severity":"high","cvss":8.3,"cves":["CVE-2026-79912"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:17:59.663+00:00","slug":"cve-2026-79912-a-vulnerability-was-detected-in-totolink"},{"id":"f2bd6f85-8fa8-4491-9a51-f3d845bdb2f4","num":2163808,"source_id":"nvd","external_id":"CVE-2026-79911","title":"CVE-2026-79911: A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the co","summary":"A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-79911","severity":"critical","cvss":10,"cves":["CVE-2026-79911"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:17:59.49+00:00","slug":"cve-2026-79911-a-security-vulnerability-has-been"},{"id":"92eb28c6-554c-4b69-9cd2-38c466c315ab","num":2163807,"source_id":"nvd","external_id":"CVE-2026-70665","title":"CVE-2026-70665: Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) e","summary":"Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists client-supplied scopes without validating them against the server's configured scope set. Under certain conditions, this allows a self-registered client to obtain scopes beyond what the server intended to grant. In DynamicClientRegistrationController#application_params, the scopes attribute is assigned directly from params[:scope] with no validation against Doorkeeper.configuration.scopes or optional_scopes. Combined with enforce_configured_scopes being off by default and Doorkeeper's ScopeChecker prioritizing application-level scopes over server-level scopes, this creates a privilege escalation path. This issue is fixed in version 1.10.4.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-70665","severity":"medium","cvss":4.2,"cves":["CVE-2026-70665"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:17:58.933+00:00","slug":"cve-2026-70665-doorkeeper-openid-connect-implements-an"},{"id":"292233e7-f905-4200-ae23-d04f51e944b6","num":2163806,"source_id":"nvd","external_id":"CVE-2026-55805","title":"CVE-2026-55805: Improper Neutralization of Input During Web Page Generation (\"Cross-site Scripting\") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions:","summary":"Improper Neutralization of Input During Web Page Generation (\"Cross-site Scripting\") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-55805","severity":"unknown","cvss":null,"cves":["CVE-2026-55805"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:17:19.74+00:00","slug":"cve-2026-55805-improper-neutralization-of-input-during"},{"id":"f1593800-c5c6-4c95-bdd0-1d6d1ebd0adb","num":2163805,"source_id":"nvd","external_id":"CVE-2026-54757","title":"CVE-2026-54757: Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is v","summary":"Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is vulnerable to server-side template injection that can lead to remote code execution. This occurs because the MDCleanInclude and MDSectionInclude Jinja2 tags re-parse untrusted Markdown content as template source code using a non-sandboxed jinja2.Environment. An attacker who controls content that Trestle renders, such as a crafted workspace Markdown file, a third-party SSP document, or a YAML lookup-table value, can inject a Jinja2 expression that traverses Python object internals to execute arbitrary operating system commands in the context of the Trestle process. This issue is fixed in versions 3.12.4 and 4.1.0.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-54757","severity":"high","cvss":7.8,"cves":["CVE-2026-54757"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:17:19.277+00:00","slug":"cve-2026-54757-compliance-trestle-trestle-is-a-python"},{"id":"466cb507-36c0-4971-902e-476d80f5c470","num":2163804,"source_id":"nvd","external_id":"CVE-2026-44476","title":"CVE-2026-44476: Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can auth","summary":"Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and obtain an access token without providing its client_secret. This occurs because the Dynamic Client Registration feature creates applications with confidential: false hard-coded, even though the registration response returns a client_secret and advertises support for the client_secret_basic and client_secret_post authentication methods; since Doorkeeper treats a blank or missing secret as valid for non-confidential (public) clients, the secret is never verified. Only projects that have explicitly enabled Dynamic Client Registration, which is disabled by default, are affected. This issue is fixed in version 1.10.0.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-44476","severity":"unknown","cvss":null,"cves":["CVE-2026-44476"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:17:04.4+00:00","slug":"cve-2026-44476-doorkeeper-is-an-oauth-2-provider-for"},{"id":"d2686b42-f868-48b7-876b-732773e69d4d","num":2163803,"source_id":"nvd","external_id":"CVE-2026-41707","title":"CVE-2026-41707: Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attacker","summary":"Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by flooding the server with dummy requests, then replay intercepted valid DPoP proofs.\nSpring Security 7.1.0\nSpring Security 7.0.0 - 7.0.6\nSpring Security 6.5.0 - 6.5.11","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-41707","severity":"high","cvss":7.4,"cves":["CVE-2026-41707"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:16:59.933+00:00","slug":"cve-2026-41707-spring-security-s"},{"id":"200767e1-d6b8-4bdf-a82c-f5cd40027200","num":2163802,"source_id":"nvd","external_id":"CVE-2026-18985","title":"CVE-2026-18985: Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1.","summary":"Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-18985","severity":"unknown","cvss":null,"cves":["CVE-2026-18985"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:16:57.913+00:00","slug":"cve-2026-18985-incorrect-authorization-vulnerability-in"},{"id":"b5f5e01b-e62a-4f95-9510-e0cf40193336","num":2163801,"source_id":"nvd","external_id":"CVE-2026-18261","title":"CVE-2026-18261: Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*.","summary":"Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-18261","severity":"unknown","cvss":null,"cves":["CVE-2026-18261"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:16:57.81+00:00","slug":"cve-2026-18261-vulnerability-in-drupal-powerful-surveys"},{"id":"ffb8813e-31fb-4e34-9ee5-e83f454ad8d8","num":2163800,"source_id":"nvd","external_id":"CVE-2026-18260","title":"CVE-2026-18260: Vulnerability in Drupal Disable Login Page. This issue affects Disable Login Page versions: *.*.","summary":"Vulnerability in Drupal Disable Login Page. This issue affects Disable Login Page versions: *.*.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-18260","severity":"unknown","cvss":null,"cves":["CVE-2026-18260"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:16:57.713+00:00","slug":"cve-2026-18260-vulnerability-in-drupal-disable-login"},{"id":"913c3f67-8975-44db-9c07-1fe4bef3be54","num":2163799,"source_id":"nvd","external_id":"CVE-2026-18259","title":"CVE-2026-18259: Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2.","summary":"Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-18259","severity":"unknown","cvss":null,"cves":["CVE-2026-18259"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:16:57.6+00:00","slug":"cve-2026-18259-observable-timing-discrepancy"},{"id":"97e85130-d801-44e6-818e-9ea6efe9e1a2","num":2163798,"source_id":"nvd","external_id":"CVE-2026-16646","title":"CVE-2026-16646: Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.","summary":"Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-16646","severity":"unknown","cvss":null,"cves":["CVE-2026-16646"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:16:57.423+00:00","slug":"cve-2026-16646-vulnerability-in-drupal-pankm-this-issue"},{"id":"4d76315c-5a55-46af-8c7f-fa81bb93c05c","num":2163797,"source_id":"nvd","external_id":"CVE-2026-16645","title":"CVE-2026-16645: Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript","summary":"Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-16645","severity":"unknown","cvss":null,"cves":["CVE-2026-16645"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:16:57.313+00:00","slug":"cve-2026-16645-missing-authorization-vulnerability-in"},{"id":"a4619890-5ea4-4057-936a-af5c8ca5bf16","num":2163796,"source_id":"nvd","external_id":"CVE-2026-16644","title":"CVE-2026-16644: Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.","summary":"Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-16644","severity":"unknown","cvss":null,"cves":["CVE-2026-16644"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:16:57.2+00:00","slug":"cve-2026-16644-incorrect-authorization-vulnerability-in"},{"id":"e321799c-de55-4f73-a475-7c57de48591b","num":2163795,"source_id":"nvd","external_id":"CVE-2026-16643","title":"CVE-2026-16643: Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*.","summary":"Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-16643","severity":"unknown","cvss":null,"cves":["CVE-2026-16643"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:16:57.1+00:00","slug":"cve-2026-16643-vulnerability-in-drupal-lunr-exposed"},{"id":"2314b46c-1d80-48e3-8b95-212eb660f14f","num":2163794,"source_id":"nvd","external_id":"CVE-2026-16642","title":"CVE-2026-16642: Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.","summary":"Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-16642","severity":"unknown","cvss":null,"cves":["CVE-2026-16642"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:16:56.997+00:00","slug":"cve-2026-16642-vulnerability-in-drupal-email-login-otp"},{"id":"224651e6-9e2c-420c-b648-a5a928fd6d68","num":2163793,"source_id":"nvd","external_id":"CVE-2026-16641","title":"CVE-2026-16641: Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.","summary":"Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-16641","severity":"unknown","cvss":null,"cves":["CVE-2026-16641"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:16:56.9+00:00","slug":"cve-2026-16641-vulnerability-in-drupal-commerce-elavon"},{"id":"1a51a369-c2f4-406c-bb36-e36525458537","num":2163792,"source_id":"nvd","external_id":"CVE-2026-16640","title":"CVE-2026-16640: Improper Neutralization of Input During Web Page Generation (\"Cross-site Scripting\") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search","summary":"Improper Neutralization of Input During Web Page Generation (\"Cross-site Scripting\") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete versions: from 0.0.0 to 1.12.0.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-16640","severity":"unknown","cvss":null,"cves":["CVE-2026-16640"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:16:56.787+00:00","slug":"cve-2026-16640-improper-neutralization-of-input-during"},{"id":"e189d7ad-6f78-4ee1-9b54-0c878f410e31","num":2163791,"source_id":"nvd","external_id":"CVE-2026-16639","title":"CVE-2026-16639: Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationali","summary":"Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-16639","severity":"unknown","cvss":null,"cves":["CVE-2026-16639"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:16:56.673+00:00","slug":"cve-2026-16639-authentication-bypass-using-an-alternate"},{"id":"a9b27e64-954c-43c8-9be2-6a2761153f33","num":2163790,"source_id":"nvd","external_id":"CVE-2026-16638","title":"CVE-2026-16638: Improper Neutralization of Input During Web Page Generation (\"Cross-site Scripting\") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versi","summary":"Improper Neutralization of Input During Web Page Generation (\"Cross-site Scripting\") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from 0.0.0 to 1.0.8.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-16638","severity":"unknown","cvss":null,"cves":["CVE-2026-16638"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:16:56.56+00:00","slug":"cve-2026-16638-improper-neutralization-of-input-during"},{"id":"211830ed-fabb-4a2d-b913-a291976d3b8e","num":2163789,"source_id":"nvd","external_id":"CVE-2026-15917","title":"CVE-2026-15917: Improper Neutralization of Input During Web Page Generation (\"Cross-site Scripting\") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupa","summary":"Improper Neutralization of Input During Web Page Generation (\"Cross-site Scripting\") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.2.*.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-15917","severity":"unknown","cvss":null,"cves":["CVE-2026-15917"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:16:56.437+00:00","slug":"cve-2026-15917-improper-neutralization-of-input-during"},{"id":"01426d9e-0d76-4d7f-8ae8-7ff0895a05d7","num":2163788,"source_id":"nvd","external_id":"CVE-2026-15916","title":"CVE-2026-15916: Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.","summary":"Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-15916","severity":"unknown","cvss":null,"cves":["CVE-2026-15916"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:16:56.32+00:00","slug":"cve-2026-15916-missing-authorization-vulnerability-in"},{"id":"12882c9e-4c9f-41d2-aaff-17043d698ef0","num":2163787,"source_id":"nvd","external_id":"CVE-2026-15088","title":"CVE-2026-15088: Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*.","summary":"Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-15088","severity":"unknown","cvss":null,"cves":["CVE-2026-15088"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T23:16:54.81+00:00","slug":"cve-2026-15088-vulnerability-in-drupal-development"},{"id":"e203975a-33bf-4e2c-a7a3-7a5f3d81e23b","num":2163786,"source_id":"nvd","external_id":"CVE-2026-80186","title":"CVE-2026-80186: A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended In","summary":"A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-80186","severity":"high","cvss":7.6,"cves":["CVE-2026-80186"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T22:17:07.587+00:00","slug":"cve-2026-80186-a-stack-based-buffer-overflow"},{"id":"69cb5bcb-60d1-4007-be54-548128e2053e","num":2163785,"source_id":"nvd","external_id":"CVE-2026-80185","title":"CVE-2026-80185: BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar un","summary":"BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-80185","severity":"medium","cvss":5.7,"cves":["CVE-2026-80185"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T22:17:07.427+00:00","slug":"cve-2026-80185-bluez-sdp-xml-c-type-confusion-via"},{"id":"6706e67f-a113-451c-b400-cf979300e941","num":2163784,"source_id":"nvd","external_id":"CVE-2026-80184","title":"CVE-2026-80184: In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) could be submitted to the token","summary":"In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) could be submitted to the token-method authentication path for reauthentication to escape their intended project scope. When an application credential token was presented with no explicit scope, Keystone would issue a new token scoped to the credential owner's default project rather than the project for which the credential was issued, bypassing the intended project boundary. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-80184","severity":"unknown","cvss":null,"cves":["CVE-2026-80184"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T22:17:07.25+00:00","slug":"cve-2026-80184-in-openstack-keystone-before-29-0-3"},{"id":"9ac2d413-f300-4170-b01c-2aecd28c4df1","num":2163783,"source_id":"nvd","external_id":"CVE-2026-80182","title":"CVE-2026-80182: In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or auth","summary":"In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain them. The delegation restrictions that block these operations did not consistently apply to all delegated token types, allowing an OAuth1-scoped token, for example, to create application credentials or authorize OAuth1 request tokens despite those operations being restricted for other delegated token types. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-80182","severity":"unknown","cvss":null,"cves":["CVE-2026-80182"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T22:17:07.067+00:00","slug":"cve-2026-80182-in-openstack-keystone-before-29-0-3"},{"id":"f3857600-1b1f-4bd1-9fe8-3d6532f4d8bf","num":2163782,"source_id":"nvd","external_id":"CVE-2026-79845","title":"CVE-2026-79845: A vulnerability was identified in code-projects Simple Inventory System 1.0. This vulnerability affects unknown code of the file /InventoryManagement/edit.php. The manipulation of","summary":"A vulnerability was identified in code-projects Simple Inventory System 1.0. This vulnerability affects unknown code of the file /InventoryManagement/edit.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-79845","severity":"high","cvss":7.3,"cves":["CVE-2026-79845"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T22:17:06.86+00:00","slug":"cve-2026-79845-a-vulnerability-was-identified-in-code"},{"id":"bdaa99f1-3d16-4e1d-8780-6a1e53a9fd56","num":2163781,"source_id":"nvd","external_id":"CVE-2026-79804","title":"CVE-2026-79804: A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affected by this issue is some unknown functionality of the file","summary":"A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affected by this issue is some unknown functionality of the file /search.php. Performing a manipulation of the argument search_box results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-79804","severity":"high","cvss":7.3,"cves":["CVE-2026-79804"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T22:17:06.67+00:00","slug":"cve-2026-79804-a-vulnerability-was-found-in"},{"id":"a1e0c98e-c642-457f-9485-e5e375adde12","num":2163780,"source_id":"nvd","external_id":"CVE-2026-78655","title":"CVE-2026-78655: Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failure","summary":"Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session.\n\nThe POST handler on challenge_path keeps the failure count as tries inside the totp_pending record in the session, raising it on each rejected code and deleting the pending record once it reaches attempts, five by default. Punk::Session carries the session in a signed cookie unless the application declares a store, and keeps no server-side record, so an earlier value of the same session stays valid until the expiry stamped inside it. A client that saves the cookie before its failed attempts and presents it again gets the pending record back with its counter, and the limit never fires. The replayed record is accepted while its own expiry, pending_ttl seconds from the challenge and 300 by default, has not passed.\n\nSessions declared with a store are not affected: the pending record and its counter then live server-side.\n\nThe attempt limit does not bound guessing of the second factor, which is left to the per-address rate limit the plugin registers on the same path, 30 requests per 60 seconds.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-78655","severity":"unknown","cvss":null,"cves":["CVE-2026-78655"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T22:17:06.537+00:00","slug":"cve-2026-78655-punk-plugin-totp-versions-before-0-05-for"},{"id":"92f13c00-e09e-4c53-8b96-ce59a64108cb","num":2163779,"source_id":"nvd","external_id":"CVE-2026-78619","title":"CVE-2026-78619: Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically.","summary":"Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically.\n\nThe helper searches the recovery model for the submitted code's digest alone, across every user's rows, so the ownership test that follows is the only thing binding a code to the account it was issued to. That test compares the row's user_id with the challenged user's id through Perl's integer coercion, and an identifier with no leading digits coerces to zero, so any two of them compare equal. User models keyed on a username, an email address or a UUID hit that case, and a numeric key compares as intended.\n\nThe challenge route feeds a submitted value to the helper once TOTP verification fails, so an attacker who knows a victim's password and holds a recovery code of their own passes the victim's second factor.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-78619","severity":"unknown","cvss":null,"cves":["CVE-2026-78619"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T22:17:06.403+00:00","slug":"cve-2026-78619-punk-plugin-totp-versions-before-0-05-for"},{"id":"56b0feb2-bd73-44d3-8958-0f203908d159","num":2163778,"source_id":"nvd","external_id":"CVE-2026-73180","title":"CVE-2026-73180: Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been esta","summary":"Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.\n\nThe following versions were EOL at the time the CVE was created but are\nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected.\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-73180","severity":"unknown","cvss":null,"cves":["CVE-2026-73180"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T22:17:06.107+00:00","slug":"cve-2026-73180-insufficient-session-expiration"},{"id":"bbbc061e-1ded-4281-abff-5e0478745321","num":2163777,"source_id":"nvd","external_id":"CVE-2026-68763","title":"CVE-2026-68763: Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: f","summary":"Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120.\n\nThe following versions were EOL at the time the CVE was created but are\nknown to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected.\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-68763","severity":"unknown","cvss":null,"cves":["CVE-2026-68763"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T22:17:05.97+00:00","slug":"cve-2026-68763-uncontrolled-resource-consumption"},{"id":"6b17fc29-5824-40d7-9083-b082dc8e98e0","num":2163776,"source_id":"nvd","external_id":"CVE-2026-68569","title":"CVE-2026-68569: Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist","summary":"Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.\n\nThe following versions were EOL at the time the CVE was created but are\nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-68569","severity":"unknown","cvss":null,"cves":["CVE-2026-68569"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T22:17:05.837+00:00","slug":"cve-2026-68569-improper-authentication-vulnerability-in"},{"id":"5234a319-1d34-4780-a929-4d8f1a7942d8","num":2163775,"source_id":"nvd","external_id":"CVE-2026-68525","title":"CVE-2026-68525: Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST bu","summary":"Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.\n\nThe following versions were EOL at the time the CVE was created but are\nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-68525","severity":"unknown","cvss":null,"cves":["CVE-2026-68525"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T22:17:05.7+00:00","slug":"cve-2026-68525-incorrect-authorization-vulnerability-in"},{"id":"dd126b90-f96c-42ef-a03e-0a81d947bbfb","num":2163774,"source_id":"nvd","external_id":"CVE-2026-66422","title":"CVE-2026-66422: Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct us","summary":"Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole().\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120.\n\nThe following versions were EOL at the time the CVE was created but are\nknown to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected.\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-66422","severity":"unknown","cvss":null,"cves":["CVE-2026-66422"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T22:17:05.56+00:00","slug":"cve-2026-66422-improper-authorization-vulnerability-in"},{"id":"1e385fcc-6d4d-4aaa-b664-06320874876b","num":2163773,"source_id":"nvd","external_id":"CVE-2026-65927","title":"CVE-2026-65927: Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule.","summary":"Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.\n\nThe following versions were EOL at the time the CVE was created but are\nknown to be affected: from 8.5.0 through 8.5.100. Other unsupported versions may also be affected.\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121 which fix the issue.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-65927","severity":"unknown","cvss":null,"cves":["CVE-2026-65927"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T22:17:05.433+00:00","slug":"cve-2026-65927-off-by-one-error-vulnerability-in-apache"},{"id":"7b559147-c409-415c-b9c8-b062834da217","num":2163772,"source_id":"nvd","external_id":"CVE-2026-65905","title":"CVE-2026-65905: Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated","summary":"Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST\nauthenticated request with a nonceCount on the upper boundary of the\nreplay window then that request is replayable once only while the\nassociated nonceCount remains within the replay window.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.\n\nThe following versions were EOL at the time the CVE was created but are\nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109. Other unsupported versions may also be affected.\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-65905","severity":"unknown","cvss":null,"cves":["CVE-2026-65905"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T22:17:05.303+00:00","slug":"cve-2026-65905-authentication-bypass-by-capture-replay"},{"id":"30e3d0ae-5c6e-48e8-9ccf-e839907ae5e5","num":2163771,"source_id":"nvd","external_id":"CVE-2026-65637","title":"CVE-2026-65637: Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 t","summary":"Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990.\n\nThis issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120.\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-65637","severity":"unknown","cvss":null,"cves":["CVE-2026-65637"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T22:17:05.177+00:00","slug":"cve-2026-65637-improper-input-validation-vulnerability"},{"id":"83143f08-5d78-4656-a4f4-caa1ba08ca7b","num":2163770,"source_id":"nvd","external_id":"CVE-2026-65183","title":"CVE-2026-65183: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socke","summary":"Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120.\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-65183","severity":"unknown","cvss":null,"cves":["CVE-2026-65183"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T22:17:05.05+00:00","slug":"cve-2026-65183-time-of-check-time-of-use-toctou-race"},{"id":"02821d27-252a-478e-ad52-0b62e69e7826","num":2163769,"source_id":"nvd","external_id":"CVE-2026-65182","title":"CVE-2026-65182: Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more res","summary":"Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-65182","severity":"unknown","cvss":null,"cves":["CVE-2026-65182"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T22:17:04.9+00:00","slug":"cve-2026-65182-improper-access-control-incorrect"},{"id":"4a4044a8-f20e-4f3a-af23-b6d37eb053f9","num":2163768,"source_id":"nvd","external_id":"CVE-2026-63404","title":"CVE-2026-63404: Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnerable to an insecure temporary file flaw that lets a loca","summary":"Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnerable to an insecure temporary file flaw that lets a local unprivileged user hijack the Redis configuration and escalate to root. It writes its startup configuration to a fixed, predictable, world-writable path, /tmp/redis.conf, only creating the file if it does not already exist and never validating it on later boots. Because /tmp is world-writable, a local unprivileged user can pre-create /tmp/redis.conf with attacker-chosen Redis directives before Faktory starts, and Faktory will use the planted file verbatim. Faktory only overrides the unixsocket, dir, and logfile options, leaving directives such as bind, protected-mode, requirepass, and loadmodule attacker-controlled. This lets an attacker silently expose the entire job queue over an unauthenticated network port with no visible error to the administrator. Because the official systemd unit runs Faktory, and the redis-server child it spawns, as root, an attacker can also supply a loadmodule directive to execute arbitrary native code in the root-owned Redis process, escalating from a local unprivileged user to root. This issue is fixed in version 1.10.0.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-63404","severity":"unknown","cvss":null,"cves":["CVE-2026-63404"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T22:17:04.76+00:00","slug":"cve-2026-63404-faktory-is-a-language-agnostic-background"},{"id":"d276a2eb-9888-4186-ab45-d0b7f9c3103f","num":2163767,"source_id":"nvd","external_id":"CVE-2026-63403","title":"CVE-2026-63403: Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the server is vulnerable to an unauthenticated denial of service in which a single malformed comm","summary":"Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the server is vulnerable to an unauthenticated denial of service in which a single malformed command crashes the entire process. Its wire protocol is line-based, and several command handlers slice or index the received line at a fixed offset, such as cmd[5:] for PUSH or qs[0] for QUEUE, without checking that a payload is present. Sending a bare verb with no payload, for example PUSH, ACK, FAIL, BEAT, PUSHB, or QUEUE, triggers a Go slice or index out-of-range panic. Because the codebase has no recover() anywhere in the command-dispatch path, an unrecovered panic in a handler goroutine terminates the whole Go process rather than just that connection, instantly disconnecting every other client, worker, and in-flight job. The attack requires only a connection to the command port and completion of the trivial handshake, with no credentials when no password is configured, and can be repeated to keep the service down indefinitely. This issue is fixed in version 1.10.0.","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-63403","severity":"unknown","cvss":null,"cves":["CVE-2026-63403"],"exploited":false,"has_exploit":false,"published_at":"2026-08-25T22:17:04.617+00:00","slug":"cve-2026-63403-faktory-is-a-language-agnostic-background"}]}