Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

454 CVEs · published 2026-09-01 to 2026-09-01

CVEs (454)

Showing 351–375 of 454

CVE ID Severity Patch CVSS Published Description
CVE-2026-84118 MEDIUM Patched 5.4 2026-09-01 Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84117 HIGH Patched 8.8 2026-09-01 Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.
CVE-2026-84061 MEDIUM 6.3 2026-09-01 A security flaw has been discovered in zhongyu09 OpenChatBI up to 0.3.0. Affected by this vulnerability is the function _validate_sql_safety of the file openchatbi/text2sql…
CVE-2026-7877 MEDIUM 6.4 2026-09-01 The WP Recipe Maker Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-call-to-action' shortcode in all versions up to, and in…
CVE-2026-79683 HIGH 8.8 2026-09-01 Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write a…
CVE-2026-58575 HIGH 8.8 2026-09-01 Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges t…
CVE-2026-53682 MEDIUM 5.3 2026-09-01 An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA …
CVE-2026-51747 NONE — 2026-09-01 Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh heartbeat information toward …
CVE-2026-51745 MEDIUM 5.3 2026-09-01 Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the primary station list via send…
CVE-2026-51744 NONE — 2026-09-01 Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronizati…
CVE-2026-51743 CRITICAL 9.1 2026-09-01 Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via se…
CVE-2026-51742 MEDIUM 5.9 2026-09-01 Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger WAN discovery logic via sending a craf…
CVE-2026-51741 NONE — 2026-09-01 Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a craft…
CVE-2026-19472 NONE — 2026-09-01 A denial-of-service security issue exists within ArmorStart® LT. The security issue stems from improper handling of a crafted HTTP PUT request sent to the embedded web serv…
CVE-2026-19471 NONE — 2026-09-01 Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, a…
CVE-2026-18765 CRITICAL 9.8 2026-09-01 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This …
CVE-2026-84200 CRITICAL Patched 9.0 2026-09-01 Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive …
CVE-2026-84199 HIGH Patched 7.7 2026-09-01 Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not valid…
CVE-2026-84196 HIGH Patched 7.7 2026-09-01 Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecti…
CVE-2026-84195 HIGH Patched 7.7 2026-09-01 Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorizatio…
CVE-2026-84194 NONE Patched &mdash; 2026-09-01 LibreNMS versions >= 23.10.0 and < 26.2.0 (fixed in 26.4.0) contain an authenticated OS command injection vulnerability in libvirt discovery. When libvirt support is enable&hellip;
CVE-2026-84193 NONE &mdash; 2026-09-01 LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer &hellip;
CVE-2026-84192 HIGH Patched 7.1 2026-09-01 LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without escaping. An at&hellip;
CVE-2026-84191 MEDIUM Patched 6.1 2026-09-01 LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages where mplsVpnVrfDescription, vrf_name, and mplsVpnVrfRouteDistinguisher fie&hellip;
CVE-2026-84190 HIGH Patched 7.2 2026-09-01 LibreNMS versions before 26.5.0 contain a remote code execution vulnerability in the AboutController where the snmpget configuration parameter is passed to shell_exec() wit&hellip;