Search
454 CVEs · published 2026-09-01 to 2026-09-01
CVEs (454)
Showing 1–25 of 454
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84642 | NONE | Patched | — | 2026-09-01 | The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this coul… |
| CVE-2026-84637 | NONE | Patched | — | 2026-09-01 | Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment… |
| CVE-2026-84639 | NONE | Patched | — | 2026-09-01 | Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and T… |
| CVE-2026-84640 | NONE | Patched | — | 2026-09-01 | A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thund… |
| CVE-2026-84641 | NONE | Patched | — | 2026-09-01 | A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This … |
| CVE-2026-83548 | NONE | — | 2026-09-01 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker c… | |
| CVE-2026-77221 | NONE | — | 2026-09-01 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-77222 | NONE | — | 2026-09-01 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-77223 | NONE | — | 2026-09-01 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-51974 | NONE | — | 2026-09-01 | An eval() injection vulnerability in the get_list function in modules/meta_parser.py in lllyasviel Fooocus 2.1.854 through 2.5.5 allows remote attackers to execute arbitrar… | |
| CVE-2026-52022 | NONE | — | 2026-09-01 | An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registration handling components | |
| CVE-2026-52023 | NONE | — | 2026-09-01 | An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_p… | |
| CVE-2026-52111 | NONE | — | 2026-09-01 | An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes authTokenKey | |
| CVE-2026-52131 | NONE | — | 2026-09-01 | llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function. | |
| CVE-2026-52132 | NONE | — | 2026-09-01 | llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a negative … | |
| CVE-2026-52295 | NONE | — | 2026-09-01 | Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows an attacker to cause a denial of service via the libavformat/iamf_writer.c component | |
| CVE-2026-19590 | NONE | — | 2026-09-01 | OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath settin… | |
| CVE-2026-19591 | NONE | — | 2026-09-01 | OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser… | |
| CVE-2026-19592 | NONE | — | 2026-09-01 | OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS automatically collected Git repository metadata without disabling the repository-loca… | |
| CVE-2026-19593 | NONE | — | 2026-09-01 | OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a reposito… | |
| CVE-2026-51788 | NONE | — | 2026-09-01 | An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification function and the accounts/models.py component | |
| CVE-2026-51934 | NONE | — | 2026-09-01 | Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co., Ltd. Tenda A18 v.15.13.07.09 allows a remote attacker to execute arbitrary code via the fromSetCmdl… | |
| CVE-2026-51956 | NONE | — | 2026-09-01 | A Broken Object Level Authorization vulnerability exists in Grashjs Atlas CMMS prior to v1.6.0. An authenticated user from one tenant can read and modify another tenant's c… | |
| CVE-2026-51769 | NONE | — | 2026-09-01 | Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to restart the cloud update check work… | |
| CVE-2026-51770 | NONE | — | 2026-09-01 | Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS sett… |