Search
454 CVEs · published 2026-09-01 to 2026-09-01
CVEs (454)
Showing 301–325 of 454
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-51757 | NONE | — | 2026-09-01 | Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflo… | |
| CVE-2026-51756 | MEDIUM | 5.9 | 2026-09-01 | Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgr… | |
| CVE-2026-51754 | NONE | — | 2026-09-01 | Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state v… | |
| CVE-2026-51752 | MEDIUM | 5.3 | 2026-09-01 | Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the… | |
| CVE-2026-51751 | NONE | — | 2026-09-01 | Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local … | |
| CVE-2026-51750 | NONE | — | 2026-09-01 | Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channe… | |
| CVE-2026-51748 | MEDIUM | 5.9 | 2026-09-01 | Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory recor… | |
| CVE-2026-19513 | HIGH | 8.1 | 2026-09-01 | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient validation of multi-f… | |
| CVE-2026-18808 | CRITICAL | 9.8 | 2026-09-01 | Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This i… | |
| CVE-2026-18210 | CRITICAL | Patched | 9.8 | 2026-09-01 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and T… |
| CVE-2026-16675 | NONE | — | 2026-09-01 | A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible consol… | |
| CVE-2026-13348 | NONE | — | 2026-09-01 | CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by perfor… | |
| CVE-2026-13337 | NONE | — | 2026-09-01 | CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into … | |
| CVE-2026-13336 | NONE | — | 2026-09-01 | CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause execution of Linux Operating system… | |
| CVE-2026-12663 | NONE | — | 2026-09-01 | A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arb… | |
| CVE-2026-12661 | NONE | — | 2026-09-01 | A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A network adjacent attacker who is authenticated could send crafted requests to th… | |
| CVE-2025-12768 | NONE | — | 2026-09-01 | A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code exe… | |
| CVE-2024-14047 | HIGH | 7.2 | 2026-09-01 | A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with ex… | |
| CVE-2024-10085 | NONE | — | 2026-09-01 | CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communication platform when a large numb… | |
| CVE-2026-84235 | NONE | — | 2026-09-01 | A denial-of-service security issue exists in the affected product. The security issue stems from a crafted CIP packet being sent crashing the module. The device requires a … | |
| CVE-2026-84149 | NONE | — | 2026-09-01 | This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could… | |
| CVE-2026-84148 | NONE | — | 2026-09-01 | This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit … | |
| CVE-2026-84147 | NONE | — | 2026-09-01 | This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attac… | |
| CVE-2026-84145 | HIGH | Patched | 7.5 | 2026-09-01 | Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another secur… |
| CVE-2026-84144 | NONE | Patched | — | 2026-09-01 | Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and … |