Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

454 CVEs · published 2026-09-01 to 2026-09-01

CVEs (454)

Showing 151–175 of 454

CVE ID Severity Patch CVSS Published Description
CVE-2026-72628 MEDIUM 6.5 2026-09-01 Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding Streams …
CVE-2026-63138 MEDIUM 6.5 2026-09-01 Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated use…
CVE-2026-63137 HIGH 8.3 2026-09-01 Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holdin…
CVE-2026-56143 MEDIUM 4.9 2026-09-01 Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated p…
CVE-2026-45221 HIGH Patched 7.8 2026-09-01 Konga before 2.1.0 contains a privilege escalation vulnerability that allows low-privileged local attackers to execute arbitrary code by planting attacker-controlled OpenSS…
CVE-2026-33465 MEDIUM 6.5 2026-09-01 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with lo…
CVE-2026-19766 CRITICAL 9.6 2026-09-01 An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated a…
CVE-2026-8712 HIGH Patched 8.3 2026-09-01 Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitr…
CVE-2026-84306 MEDIUM Patched 6.5 2026-09-01 Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.6 and 5.7.6, packages/panels/src/Auth/MultiFactor/App/AppAuthen…
CVE-2026-84305 NONE Patched — 2026-09-01 sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse.format(sql, reindent=True) and sqlformat --reindent route attacker-controlled parenthesi…
CVE-2026-84304 NONE Patched — 2026-09-01 gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBu…
CVE-2026-84303 NONE Patched — 2026-09-01 gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names…
CVE-2026-83551 HIGH 7.2 2026-09-01 Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an a…
CVE-2026-81846 LOW Patched 3.5 2026-09-01 An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through Us…
CVE-2026-52295 NONE — 2026-09-01 Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows an attacker to cause a denial of service via the libavformat/iamf_writer.c component
CVE-2026-52132 NONE — 2026-09-01 llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a negative …
CVE-2026-52131 NONE — 2026-09-01 llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function.
CVE-2026-52130 HIGH 7.5 2026-09-01 llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to-grammar.cpp, resulting in a denial of service.
CVE-2026-52111 NONE &mdash; 2026-09-01 An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes authTokenKey
CVE-2026-52023 NONE &mdash; 2026-09-01 An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_p&hellip;
CVE-2026-52022 NONE &mdash; 2026-09-01 An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registration handling components
CVE-2026-51974 NONE &mdash; 2026-09-01 An eval() injection vulnerability in the get_list function in modules/meta_parser.py in lllyasviel Fooocus 2.1.854 through 2.5.5 allows remote attackers to execute arbitrar&hellip;
CVE-2026-19593 NONE &mdash; 2026-09-01 OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a reposito&hellip;
CVE-2026-19592 NONE &mdash; 2026-09-01 OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS automatically collected Git repository metadata without disabling the repository-loca&hellip;
CVE-2026-19591 NONE &mdash; 2026-09-01 OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser&hellip;