Search
454 CVEs · published 2026-09-01 to 2026-09-01
CVEs (454)
Showing 376–400 of 454
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-84189 | HIGH | Patched | 8.1 | 2026-09-01 | LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the de… |
| CVE-2026-84188 | MEDIUM | Patched | 4.8 | 2026-09-01 | LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.<graphtype> configuration settings, which are echoed verbatim without HTM… |
| CVE-2026-84187 | HIGH | 8.2 | 2026-09-01 | AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticated attackers to mark arbitrary scheduled broadcasts as failed … | |
| CVE-2026-83595 | HIGH | 8.1 | 2026-09-01 | AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform state-changing actions by crafting GET requests that … | |
| CVE-2026-77194 | MEDIUM | Patched | 5.3 | 2026-09-01 | The Simple Membership plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in versions up to, and including, 4.8.0. This is… |
| CVE-2026-76111 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke admi… | |
| CVE-2026-18550 | CRITICAL | 9.8 | 2026-09-01 | The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to i… | |
| CVE-2026-11873 | MEDIUM | 6.5 | 2026-09-01 | An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed request… | |
| CVE-2026-10420 | MEDIUM | Patched | 5.5 | 2026-09-01 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be. |
| CVE-2025-15613 | MEDIUM | 6.5 | 2026-09-01 | Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attacker with permission to create Kyverno (Cluster)Polici… | |
| CVE-2023-54356 | LOW | Patched | 3.7 | 2026-09-01 | Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These… |
| CVE-2026-84165 | NONE | — | 2026-09-01 | A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticat… | |
| CVE-2026-84059 | HIGH | 7.4 | 2026-09-01 | A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 20260704. The affected element is the function ArmAngstromInstructionSet of the file /CGI?RestApi=SetHostname. Ex… | |
| CVE-2026-82927 | MEDIUM | Patched | 5.5 | 2026-09-01 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e. |
| CVE-2026-82926 | MEDIUM | 5.5 | 2026-09-01 | NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a. | |
| CVE-2026-4813 | NONE | — | 2026-09-01 | A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticated administrators to execute code remotely. The XML/XSLT proces… | |
| CVE-2026-59681 | HIGH | 8.8 | 2026-09-01 | A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory configuration values to execute arbitrary commands as root on the… | |
| CVE-2026-59680 | HIGH | 8.0 | 2026-09-01 | An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb r… | |
| CVE-2026-25706 | HIGH | 7.5 | 2026-09-01 | Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - … | |
| CVE-2026-19914 | HIGH | 7.2 | 2026-09-01 | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_order' parameter in all versions up to, and including, 2.12.1 due t… | |
| CVE-2026-16788 | MEDIUM | 6.4 | 2026-09-01 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_projects_output Shortcode in all versio… | |
| CVE-2026-16786 | MEDIUM | 6.4 | 2026-09-01 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode in all ve… | |
| CVE-2026-15101 | MEDIUM | 6.4 | 2026-09-01 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 8.7.4 due to insu… | |
| CVE-2026-78363 | MEDIUM | Patched | 4.8 | 2026-09-01 | The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcodes in user-submitted values from being executed when it merges those values into a message that it lat… |
| CVE-2026-74916 | MEDIUM | Patched | 6.5 | 2026-09-01 | The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested wit… |