Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

454 CVEs · published 2026-09-01 to 2026-09-01

CVEs (454)

Showing 376–400 of 454

CVE ID Severity Patch CVSS Published Description
CVE-2026-84189 HIGH Patched 8.1 2026-09-01 LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the de…
CVE-2026-84188 MEDIUM Patched 4.8 2026-09-01 LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.<graphtype> configuration settings, which are echoed verbatim without HTM&hellip;
CVE-2026-84187 HIGH 8.2 2026-09-01 AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticated attackers to mark arbitrary scheduled broadcasts as failed &hellip;
CVE-2026-83595 HIGH 8.1 2026-09-01 AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform state-changing actions by crafting GET requests that &hellip;
CVE-2026-77194 MEDIUM Patched 5.3 2026-09-01 The Simple Membership plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in versions up to, and including, 4.8.0. This is&hellip;
CVE-2026-76111 HIGH 8.8 2026-09-01 Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke admi&hellip;
CVE-2026-18550 CRITICAL 9.8 2026-09-01 The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to i&hellip;
CVE-2026-11873 MEDIUM 6.5 2026-09-01 An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed request&hellip;
CVE-2026-10420 MEDIUM Patched 5.5 2026-09-01 Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be.
CVE-2025-15613 MEDIUM 6.5 2026-09-01 Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attacker with permission to create Kyverno (Cluster)Polici&hellip;
CVE-2023-54356 LOW Patched 3.7 2026-09-01 Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These&hellip;
CVE-2026-84165 NONE &mdash; 2026-09-01 A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticat&hellip;
CVE-2026-84059 HIGH 7.4 2026-09-01 A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 20260704. The affected element is the function ArmAngstromInstructionSet of the file /CGI?RestApi=SetHostname. Ex&hellip;
CVE-2026-82927 MEDIUM Patched 5.5 2026-09-01 Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e.
CVE-2026-82926 MEDIUM 5.5 2026-09-01 NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a.
CVE-2026-4813 NONE &mdash; 2026-09-01 A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticated administrators to execute code remotely. The XML/XSLT proces&hellip;
CVE-2026-59681 HIGH 8.8 2026-09-01 A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory configuration values to execute arbitrary commands as root on the&hellip;
CVE-2026-59680 HIGH 8.0 2026-09-01 An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb r&hellip;
CVE-2026-25706 HIGH 7.5 2026-09-01 Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - &hellip;
CVE-2026-19914 HIGH 7.2 2026-09-01 The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_order' parameter in all versions up to, and including, 2.12.1 due t&hellip;
CVE-2026-16788 MEDIUM 6.4 2026-09-01 The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_projects_output Shortcode in all versio&hellip;
CVE-2026-16786 MEDIUM 6.4 2026-09-01 The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode in all ve&hellip;
CVE-2026-15101 MEDIUM 6.4 2026-09-01 The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 8.7.4 due to insu&hellip;
CVE-2026-78363 MEDIUM Patched 4.8 2026-09-01 The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcodes in user-submitted values from being executed when it merges those values into a message that it lat&hellip;
CVE-2026-74916 MEDIUM Patched 6.5 2026-09-01 The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested wit&hellip;