Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

454 CVEs · published 2026-09-01 to 2026-09-01

CVEs (454)

Showing 1–25 of 454

CVE ID Severity Patch CVSS Published Description
CVE-2026-9637 NONE — 2026-09-01 A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length durin…
CVE-2026-9634 NONE — 2026-09-01 A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one or …
CVE-2026-9633 NONE — 2026-09-01 A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one or…
CVE-2026-9625 NONE — 2026-09-01 A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic service to c…
CVE-2026-9624 NONE — 2026-09-01 A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length valida…
CVE-2026-9622 NONE — 2026-09-01 A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic service to crash, r…
CVE-2026-9621 NONE — 2026-09-01 A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the …
CVE-2026-8712 HIGH Patched 8.3 2026-09-01 Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitr…
CVE-2026-84642 NONE Patched — 2026-09-01 The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this coul…
CVE-2026-84641 NONE Patched — 2026-09-01 A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This …
CVE-2026-84640 NONE Patched — 2026-09-01 A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thund…
CVE-2026-84639 NONE Patched — 2026-09-01 Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and T…
CVE-2026-84637 NONE Patched — 2026-09-01 Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment…
CVE-2026-84483 MEDIUM 5.3 2026-09-01 WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens …
CVE-2026-84482 HIGH 8.8 2026-09-01 WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate refe…
CVE-2026-84481 NONE — 2026-09-01 WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to…
CVE-2026-84480 CRITICAL 9.8 2026-09-01 WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefi…
CVE-2026-84479 CRITICAL 9.1 2026-09-01 WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoM…
CVE-2026-84478 HIGH 7.3 2026-09-01 WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying…
CVE-2026-84477 MEDIUM 5.4 2026-09-01 AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts. Unauthent…
CVE-2026-84476 HIGH 7.5 2026-09-01 WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimi…
CVE-2026-84470 MEDIUM 6.4 2026-09-01 A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_gro…
CVE-2026-84423 HIGH 7.3 2026-09-01 A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controllers/resource.go of the component upload-resource API. Such manip…
CVE-2026-84375 HIGH Patched 7.5 2026-09-01 js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping…
CVE-2026-84374 HIGH Patched 7.5 2026-09-01 Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method res…