{"meta":{"window_days":7,"count":10},"data":[{"cve_id":"CVE-2026-76008","severity":"CRITICAL","cvss":10,"cvss_version":null,"kev":false,"epss":null,"epss_percentile":null,"published":"2026-08-19","vendor":null,"product":null,"description":"A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflow. The attack can be initiated remotely.","url":"https://dbcve.org/cve/CVE-2026-76008"},{"cve_id":"CVE-2026-70921","severity":"CRITICAL","cvss":10,"cvss_version":null,"kev":false,"epss":null,"epss_percentile":null,"published":"2026-08-18","vendor":null,"product":null,"description":"Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Hyperion Financial Management.  While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).","url":"https://dbcve.org/cve/CVE-2026-70921"},{"cve_id":"CVE-2026-70880","severity":"CRITICAL","cvss":10,"cvss_version":null,"kev":false,"epss":null,"epss_percentile":null,"published":"2026-08-18","vendor":null,"product":null,"description":"Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Data Relationship Management.  While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).","url":"https://dbcve.org/cve/CVE-2026-70880"},{"cve_id":"CVE-2026-61241","severity":"CRITICAL","cvss":10,"cvss_version":null,"kev":false,"epss":null,"epss_percentile":null,"published":"2026-08-18","vendor":null,"product":null,"description":"Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.  While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).","url":"https://dbcve.org/cve/CVE-2026-61241"},{"cve_id":"CVE-2026-75784","severity":"CRITICAL","cvss":10,"cvss_version":null,"kev":false,"epss":null,"epss_percentile":null,"published":"2026-08-18","vendor":null,"product":null,"description":"A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.","url":"https://dbcve.org/cve/CVE-2026-75784"},{"cve_id":"CVE-2026-73343","severity":"CRITICAL","cvss":10,"cvss_version":null,"kev":false,"epss":null,"epss_percentile":null,"published":"2026-08-18","vendor":null,"product":null,"description":"Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.","url":"https://dbcve.org/cve/CVE-2026-73343"},{"cve_id":"CVE-2026-75874","severity":"CRITICAL","cvss":10,"cvss_version":null,"kev":false,"epss":null,"epss_percentile":null,"published":"2026-08-18","vendor":null,"product":null,"description":"Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.","url":"https://dbcve.org/cve/CVE-2026-75874"},{"cve_id":"CVE-2026-74253","severity":"CRITICAL","cvss":10,"cvss_version":null,"kev":false,"epss":null,"epss_percentile":null,"published":"2026-08-17","vendor":null,"product":null,"description":"Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 - Regular Labs Sourcerer before 14.0.0 processes {source} blocks found in Joomla’s final rendered HTML without reliably determining where that code originated.","url":"https://dbcve.org/cve/CVE-2026-74253"},{"cve_id":"CVE-2026-74843","severity":"CRITICAL","cvss":10,"cvss_version":null,"kev":false,"epss":null,"epss_percentile":null,"published":"2026-08-17","vendor":null,"product":null,"description":"A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pingortrace.cgi of the component Export Pingortrace CGI. Executing a manipulation of the argument HTTP_COOKIE can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.","url":"https://dbcve.org/cve/CVE-2026-74843"},{"cve_id":"CVE-2026-19977","severity":"CRITICAL","cvss":10,"cvss_version":null,"kev":false,"epss":null,"epss_percentile":null,"published":"2026-08-17","vendor":null,"product":null,"description":"A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in improper authentication. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","url":"https://dbcve.org/cve/CVE-2026-19977"}],"attribution":{"source":"dbcve.org","license":"CC-BY-4.0","terms":"Base CVE data derived from NVD (public domain). dbcve.org enrichment is CC-BY-4.0 — attribution to dbcve.org required.","docs":"https://dbcve.org/api"}}