CVE ID :CVE-2026-8763 Published : Aug. 3, 2026, 1:16 a.m. | 26 minutes ago Description :In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This…
CVE-2026-59650 – MTI/A0 DH agreement exponentiates unvalidated peer value
CVE ID :CVE-2026-59650 Published : Aug. 3, 2026, 1:16 a.m. | 26 minutes ago Description :In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects…
CVE-2026-59649 – OpenPGP user-attribute subpacket length bounded only by JVM max memory
CVE ID :CVE-2026-59649 Published : Aug. 3, 2026, 1:16 a.m. | 26 minutes ago Description :In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This…
CVE-2026-59646 – DTLS handshake reassembler allocates buffer from unchecked 24-bit length
CVE ID :CVE-2026-59646 Published : Aug. 3, 2026, 1:16 a.m. | 26 minutes ago Description :In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue…
CVE-2026-59645 – OER parser recurses without depth limit on self-referential IEEE 1609.2 schema
CVE ID :CVE-2026-59645 Published : Aug. 3, 2026, 1:16 a.m. | 26 minutes ago Description :In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema….
CVE-2026-18577 – Incomplete patch leads to administrative account takeover
CVE ID :CVE-2026-18577 Published : Aug. 2, 2026, 11:16 p.m. | 26 minutes ago Description :An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 Severity:…
CVE-2026-65321 – PyAthena 3.35.4 SQL Injection via DefaultParameterFormatter DELETE/CTAS
CVE ID :CVE-2026-65321 Published : Aug. 2, 2026, 3:16 p.m. | 8 hours, 26 minutes ago Description :PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL…
CVE-2026-68581 – Vikunja 0.22.0 through 2.3.0 Authentication Bypass via Principal ID Collision
CVE ID :CVE-2026-68581 Published : Aug. 2, 2026, 1:16 p.m. | 10 hours, 26 minutes ago Description :Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user…
CVE-2026-68579 – FreeRDP before 3.30.0 Heap Overflow via CliprdrStream_Read
CVE ID :CVE-2026-68579 Published : Aug. 2, 2026, 1:16 p.m. | 10 hours, 26 minutes ago Description :FreeRDP before 3.30.0 ( Severity: 9.6 | CRITICAL Visit the link for more details, such as CVSS…
CVE-2026-67356 – ArcadeDB before 26.7.3 Privilege Escalation via JavaScript Trigger
CVE ID :CVE-2026-67356 Published : Aug. 2, 2026, 1:16 p.m. | 10 hours, 26 minutes ago Description :ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to…