Search
454 CVEs · published 2026-09-01 to 2026-09-01
CVEs (454)
Showing 26–50 of 454
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-19118 | NONE | Patched | — | 2026-09-01 | A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticat… |
| CVE-2026-18730 | NONE | Patched | — | 2026-09-01 | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send craft… |
| CVE-2023-54391 | CRITICAL | Patched | 9.8 | 2026-09-01 | Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers… |
| CVE-2026-84470 | MEDIUM | 6.4 | 2026-09-01 | A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_gro… | |
| CVE-2026-84371 | MEDIUM | Patched | 5.4 | 2026-09-01 | ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.1… |
| CVE-2026-84370 | HIGH | Patched | 8.2 | 2026-09-01 | SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the op… |
| CVE-2026-84369 | MEDIUM | Patched | 6.1 | 2026-09-01 | SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the op… |
| CVE-2026-84368 | LOW | Patched | 3.7 | 2026-09-01 | joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.6 and 18.2.5, the @hapi/joi package through 17.1.1 and the successor joi pac… |
| CVE-2026-84367 | LOW | Patched | 3.7 | 2026-09-01 | joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.5 and 18.2.4, joi's lib/types/keys.js internals.rename() implementation used… |
| CVE-2026-84366 | HIGH | Patched | 7.4 | 2026-09-01 | Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-… |
| CVE-2026-84365 | MEDIUM | Patched | 6.5 | 2026-09-01 | Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix released for CVE-2026-39408 does not cover every tr… |
| CVE-2026-84364 | MEDIUM | Patched | 5.3 | 2026-09-01 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, when parseBody() expands dot-separated form field names into nested o… |
| CVE-2026-84363 | MEDIUM | Patched | 5.9 | 2026-09-01 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, Hono's query helpers treat a question mark after a literal hash fragm… |
| CVE-2026-84361 | NONE | Patched | — | 2026-09-01 | Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted co… |
| CVE-2026-84311 | NONE | Patched | — | 2026-09-01 | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.ext… |
| CVE-2026-84310 | NONE | Patched | — | 2026-09-01 | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes… |
| CVE-2026-84287 | MEDIUM | 4.3 | 2026-09-01 | A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is some unknown functionality of the file gateway/platforms/api_server.py of the component… | |
| CVE-2026-73783 | MEDIUM | 4.9 | 2026-09-01 | Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service conditi… | |
| CVE-2026-73782 | HIGH | 8.8 | 2026-09-01 | A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulne… | |
| CVE-2026-73781 | HIGH | 8.4 | 2026-09-01 | A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a… | |
| CVE-2026-73780 | HIGH | 8.3 | 2026-09-01 | A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a… | |
| CVE-2026-73779 | HIGH | 8.2 | 2026-09-01 | Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authenti… | |
| CVE-2026-73778 | HIGH | 8.1 | 2026-09-01 | A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vuln… | |
| CVE-2026-73777 | HIGH | 8.1 | 2026-09-01 | Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authenticati… | |
| CVE-2026-73776 | HIGH | 7.9 | 2026-09-01 | A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation could allow an authenticated malicious actor with admi… |