Search
454 CVEs · published 2026-09-01 to 2026-09-01
CVEs (454)
Showing 176–200 of 454
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-19590 | NONE | — | 2026-09-01 | OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath settin… | |
| CVE-2024-7953 | NONE | — | 2026-09-01 | A vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a threat actor could creat… | |
| CVE-2024-7952 | NONE | — | 2026-09-01 | A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be reached without authenticatio… | |
| CVE-2026-58566 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation o… | |
| CVE-2026-51956 | NONE | — | 2026-09-01 | A Broken Object Level Authorization vulnerability exists in Grashjs Atlas CMMS prior to v1.6.0. An authenticated user from one tenant can read and modify another tenant's c… | |
| CVE-2026-51934 | NONE | — | 2026-09-01 | Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co., Ltd. Tenda A18 v.15.13.07.09 allows a remote attacker to execute arbitrary code via the fromSetCmdl… | |
| CVE-2026-51788 | NONE | — | 2026-09-01 | An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification function and the accounts/models.py component | |
| CVE-2026-84270 | MEDIUM | 4.3 | 2026-09-01 | A flaw was found in the MTP backend in gvfs. When reading a file from a mounted MTP device, do_read() in gvfsbackendmtp.c trusts the data length returned by the device with… | |
| CVE-2026-84269 | MEDIUM | 6.5 | 2026-09-01 | A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested b… | |
| CVE-2026-84268 | HIGH | 8.8 | 2026-09-01 | A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the … | |
| CVE-2026-84267 | MEDIUM | 4.3 | 2026-09-01 | A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer with a certain length but the func… | |
| CVE-2026-84232 | MEDIUM | 5.4 | 2026-09-01 | A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for .… | |
| CVE-2026-84207 | MEDIUM | Patched | 5.4 | 2026-09-01 | Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send and WebSocket Trigger nodes, allowing authenticated users to connect to internal services. Attackers … |
| CVE-2026-84206 | MEDIUM | Patched | 4.3 | 2026-09-01 | Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-del… |
| CVE-2026-84205 | MEDIUM | 6.5 | 2026-09-01 | GROWI contains an access control vulnerability in the GET /_api/v3/revisions/:id endpoint that validates access against a query parameter but returns the revision identifie… | |
| CVE-2026-84204 | MEDIUM | 6.5 | 2026-09-01 | GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retri… | |
| CVE-2026-84203 | HIGH | 8.1 | 2026-09-01 | Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a sto… | |
| CVE-2026-84202 | HIGH | 8.8 | 2026-09-01 | ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can cra… | |
| CVE-2026-84201 | HIGH | 7.1 | 2026-09-01 | appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch tools, allowing attackers to write files outside the inte… | |
| CVE-2026-84153 | MEDIUM | 6.3 | 2026-09-01 | A vulnerability was determined in Xinhu Rainrock RockOA up to 2.3.2. The impacted element is the function toaddval of the file /index.php?m=index&a=publicsavevalue&ajaxbool… | |
| CVE-2026-79687 | CRITICAL | 9.0 | 2026-09-01 | Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this v… | |
| CVE-2026-79682 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary … | |
| CVE-2026-61779 | HIGH | 7.8 | 2026-09-01 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … | |
| CVE-2026-61778 | HIGH | 7.8 | 2026-09-01 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … | |
| CVE-2026-61777 | HIGH | 7.8 | 2026-09-01 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … |