Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

454 CVEs · published 2026-09-01 to 2026-09-01

CVEs (454)

Showing 176–200 of 454

CVE ID Severity Patch CVSS Published Description
CVE-2026-19590 NONE — 2026-09-01 OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath settin…
CVE-2024-7953 NONE — 2026-09-01 A vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a threat actor could creat…
CVE-2024-7952 NONE — 2026-09-01 A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be reached without authenticatio…
CVE-2026-58566 HIGH 8.8 2026-09-01 Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation o…
CVE-2026-51956 NONE — 2026-09-01 A Broken Object Level Authorization vulnerability exists in Grashjs Atlas CMMS prior to v1.6.0. An authenticated user from one tenant can read and modify another tenant's c…
CVE-2026-51934 NONE — 2026-09-01 Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co., Ltd. Tenda A18 v.15.13.07.09 allows a remote attacker to execute arbitrary code via the fromSetCmdl…
CVE-2026-51788 NONE — 2026-09-01 An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification function and the accounts/models.py component
CVE-2026-84270 MEDIUM 4.3 2026-09-01 A flaw was found in the MTP backend in gvfs. When reading a file from a mounted MTP device, do_read() in gvfsbackendmtp.c trusts the data length returned by the device with…
CVE-2026-84269 MEDIUM 6.5 2026-09-01 A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested b…
CVE-2026-84268 HIGH 8.8 2026-09-01 A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the …
CVE-2026-84267 MEDIUM 4.3 2026-09-01 A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer with a certain length but the func…
CVE-2026-84232 MEDIUM 5.4 2026-09-01 A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for .…
CVE-2026-84207 MEDIUM Patched 5.4 2026-09-01 Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send and WebSocket Trigger nodes, allowing authenticated users to connect to internal services. Attackers …
CVE-2026-84206 MEDIUM Patched 4.3 2026-09-01 Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-del…
CVE-2026-84205 MEDIUM 6.5 2026-09-01 GROWI contains an access control vulnerability in the GET /_api/v3/revisions/:id endpoint that validates access against a query parameter but returns the revision identifie…
CVE-2026-84204 MEDIUM 6.5 2026-09-01 GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retri…
CVE-2026-84203 HIGH 8.1 2026-09-01 Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a sto…
CVE-2026-84202 HIGH 8.8 2026-09-01 ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can cra…
CVE-2026-84201 HIGH 7.1 2026-09-01 appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch tools, allowing attackers to write files outside the inte…
CVE-2026-84153 MEDIUM 6.3 2026-09-01 A vulnerability was determined in Xinhu Rainrock RockOA up to 2.3.2. The impacted element is the function toaddval of the file /index.php?m=index&a=publicsavevalue&ajaxbool…
CVE-2026-79687 CRITICAL 9.0 2026-09-01 Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this v…
CVE-2026-79682 HIGH 8.8 2026-09-01 Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary …
CVE-2026-61779 HIGH 7.8 2026-09-01 NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …
CVE-2026-61778 HIGH 7.8 2026-09-01 NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …
CVE-2026-61777 HIGH 7.8 2026-09-01 NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …