Search
454 CVEs · published 2026-09-01 to 2026-09-01
CVEs (454)
Showing 1–25 of 454
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-54356 | LOW | Patched | 3.7 | 2026-09-01 | Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These… |
| CVE-2023-54391 | CRITICAL | Patched | 9.8 | 2026-09-01 | Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers… |
| CVE-2024-10085 | NONE | — | 2026-09-01 | CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communication platform when a large numb… | |
| CVE-2024-14047 | HIGH | 7.2 | 2026-09-01 | A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with ex… | |
| CVE-2024-7952 | NONE | — | 2026-09-01 | A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be reached without authenticatio… | |
| CVE-2024-7953 | NONE | — | 2026-09-01 | A vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a threat actor could creat… | |
| CVE-2025-12768 | NONE | — | 2026-09-01 | A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code exe… | |
| CVE-2025-15613 | MEDIUM | 6.5 | 2026-09-01 | Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attacker with permission to create Kyverno (Cluster)Polici… | |
| CVE-2026-10195 | HIGH | 8.8 | 2026-09-01 | The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 8.0.1. This is due to insufficient input sanitization of the FFmpe… | |
| CVE-2026-10420 | MEDIUM | Patched | 5.5 | 2026-09-01 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be. |
| CVE-2026-11873 | MEDIUM | 6.5 | 2026-09-01 | An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed request… | |
| CVE-2026-12661 | NONE | — | 2026-09-01 | A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A network adjacent attacker who is authenticated could send crafted requests to th… | |
| CVE-2026-12663 | NONE | — | 2026-09-01 | A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arb… | |
| CVE-2026-12747 | MEDIUM | 6.4 | 2026-09-01 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, 3.29.… | |
| CVE-2026-13203 | MEDIUM | 6.4 | 2026-09-01 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_id' shortcode attribute of the dslc_mod… | |
| CVE-2026-13336 | NONE | — | 2026-09-01 | CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause execution of Linux Operating system… | |
| CVE-2026-13337 | NONE | — | 2026-09-01 | CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into … | |
| CVE-2026-13348 | NONE | — | 2026-09-01 | CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by perfor… | |
| CVE-2026-13611 | MEDIUM | Patched | 5.3 | 2026-09-01 | The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints, allowing unauthenticated attackers to disclose the patient r… |
| CVE-2026-15101 | MEDIUM | 6.4 | 2026-09-01 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 8.7.4 due to insu… | |
| CVE-2026-16675 | NONE | — | 2026-09-01 | A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible consol… | |
| CVE-2026-16786 | MEDIUM | 6.4 | 2026-09-01 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode in all ve… | |
| CVE-2026-16787 | MEDIUM | 6.4 | 2026-09-01 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode in all versions up to… | |
| CVE-2026-16788 | MEDIUM | 6.4 | 2026-09-01 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_projects_output Shortcode in all versio… | |
| CVE-2026-17589 | MEDIUM | 4.9 | 2026-09-01 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'product_order' parameter in all versions up to, and including, 5.9.… |