Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

454 CVEs · published 2026-09-01 to 2026-09-01

CVEs (454)

Showing 1–25 of 454

CVE ID Severity Patch CVSS Published Description
CVE-2023-54356 LOW Patched 3.7 2026-09-01 Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These…
CVE-2023-54391 CRITICAL Patched 9.8 2026-09-01 Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers…
CVE-2024-10085 NONE — 2026-09-01 CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communication platform when a large numb…
CVE-2024-14047 HIGH 7.2 2026-09-01 A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with ex…
CVE-2024-7952 NONE — 2026-09-01 A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be reached without authenticatio…
CVE-2024-7953 NONE — 2026-09-01 A vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a threat actor could creat…
CVE-2025-12768 NONE — 2026-09-01 A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code exe…
CVE-2025-15613 MEDIUM 6.5 2026-09-01 Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attacker with permission to create Kyverno (Cluster)Polici…
CVE-2026-10195 HIGH 8.8 2026-09-01 The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 8.0.1. This is due to insufficient input sanitization of the FFmpe…
CVE-2026-10420 MEDIUM Patched 5.5 2026-09-01 Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be.
CVE-2026-11873 MEDIUM 6.5 2026-09-01 An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed request…
CVE-2026-12661 NONE — 2026-09-01 A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition.  A network adjacent attacker who is authenticated could send crafted requests to th…
CVE-2026-12663 NONE — 2026-09-01 A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arb…
CVE-2026-12747 MEDIUM 6.4 2026-09-01 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, 3.29.…
CVE-2026-13203 MEDIUM 6.4 2026-09-01 The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_id' shortcode attribute of the dslc_mod…
CVE-2026-13336 NONE — 2026-09-01 CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause execution of Linux Operating system…
CVE-2026-13337 NONE — 2026-09-01 CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into …
CVE-2026-13348 NONE — 2026-09-01 CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by perfor…
CVE-2026-13611 MEDIUM Patched 5.3 2026-09-01 The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints, allowing unauthenticated attackers to disclose the patient r…
CVE-2026-15101 MEDIUM 6.4 2026-09-01 The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 8.7.4 due to insu…
CVE-2026-16675 NONE — 2026-09-01 A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible consol…
CVE-2026-16786 MEDIUM 6.4 2026-09-01 The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode in all ve…
CVE-2026-16787 MEDIUM 6.4 2026-09-01 The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode in all versions up to…
CVE-2026-16788 MEDIUM 6.4 2026-09-01 The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_projects_output Shortcode in all versio…
CVE-2026-17589 MEDIUM 4.9 2026-09-01 The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'product_order' parameter in all versions up to, and including, 5.9.…