Search
454 CVEs · published 2026-09-01 to 2026-09-01
CVEs (454)
Showing 251–275 of 454
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-83609 | NONE | Patched | — | 2026-09-01 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0 until 0.9.12, the shared reg() builder in lib/grammar.j… |
| CVE-2026-83608 | NONE | Patched | — | 2026-09-01 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom … |
| CVE-2026-83607 | NONE | Patched | — | 2026-09-01 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.14 and 0.9.11, and in xmldom … |
| CVE-2026-83606 | NONE | Patched | — | 2026-09-01 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.9 until 0.9.11, the processing-instruction product… |
| CVE-2026-83605 | NONE | Patched | — | 2026-09-01 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.14 and 0.9.11, and in xmldom … |
| CVE-2026-83557 | MEDIUM | Patched | 5.6 | 2026-09-01 | DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It … |
| CVE-2026-79686 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass … | |
| CVE-2026-79685 | MEDIUM | 6.5 | 2026-09-01 | Dell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to gain unauthorize… | |
| CVE-2026-78012 | CRITICAL | 9.8 | 2026-09-01 | An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generat… | |
| CVE-2026-75538 | NONE | Patched | — | 2026-09-01 | An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an incorrect packet length calculation to o… |
| CVE-2026-74994 | NONE | Patched | — | 2026-09-01 | The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all dire… |
| CVE-2026-74835 | NONE | Patched | — | 2026-09-01 | The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from O… |
| CVE-2026-73812 | NONE | Patched | — | 2026-09-01 | httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 identifies as a probable s… |
| CVE-2026-73276 | NONE | Patched | — | 2026-09-01 | Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities. This issue affects OTP from OTP 22.2 before OTP 27.3.4… |
| CVE-2026-73270 | NONE | Patched | — | 2026-09-01 | Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory b… |
| CVE-2026-71562 | NONE | Patched | — | 2026-09-01 | Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP inets httpc allows a malicious or compromised HTTP server to degrade availability by returnin… |
| CVE-2026-71380 | NONE | Patched | — | 2026-09-01 | Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending… |
| CVE-2026-70409 | NONE | Patched | — | 2026-09-01 | Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP server to degrade availability by returning a re… |
| CVE-2026-70405 | NONE | Patched | — | 2026-09-01 | Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP snmp allows a remote attacker to degrade availability by sending an SNMP message containing a… |
| CVE-2026-70399 | NONE | Patched | — | 2026-09-01 | Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening… |
| CVE-2026-69664 | NONE | Patched | — | 2026-09-01 | Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending… |
| CVE-2026-66835 | NONE | Patched | — | 2026-09-01 | Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by prefixing the reque… |
| CVE-2026-66357 | NONE | Patched | — | 2026-09-01 | httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Every CRLF followed by a non-CRLF octet unconditionally starts a new heade… |
| CVE-2026-5480 | NONE | — | 2026-09-01 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have be… | |
| CVE-2026-59696 | NONE | Patched | — | 2026-09-01 | Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP stdlib allows a remote attacker to degrade availability by supplying a URI whose port compone… |