Search
454 CVEs · published 2026-09-01 to 2026-09-01
CVEs (454)
Showing 1–25 of 454
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-76658 | CRITICAL | 10.0 | 2026-09-01 | A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to… | |
| CVE-2026-76657 | CRITICAL | 10.0 | 2026-09-01 | Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing aut… | |
| CVE-2026-84147 | NONE | — | 2026-09-01 | This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attac… | |
| CVE-2026-83772 | CRITICAL | 9.9 | 2026-09-01 | A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-repor… | |
| CVE-2026-84480 | CRITICAL | 9.8 | 2026-09-01 | WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefi… | |
| CVE-2026-84372 | CRITICAL | Patched | 9.8 | 2026-09-01 | Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replicatio… |
| CVE-2023-54391 | CRITICAL | Patched | 9.8 | 2026-09-01 | Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers… |
| CVE-2026-73749 | CRITICAL | 9.8 | 2026-09-01 | Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulne… | |
| CVE-2026-78012 | CRITICAL | 9.8 | 2026-09-01 | An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generat… | |
| CVE-2026-18808 | CRITICAL | 9.8 | 2026-09-01 | Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This i… | |
| CVE-2026-18210 | CRITICAL | Patched | 9.8 | 2026-09-01 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and T… |
| CVE-2026-18765 | CRITICAL | 9.8 | 2026-09-01 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This … | |
| CVE-2026-18550 | CRITICAL | 9.8 | 2026-09-01 | The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to i… | |
| CVE-2026-75865 | CRITICAL | 9.8 | 2026-09-01 | The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing… | |
| CVE-2026-19766 | CRITICAL | 9.6 | 2026-09-01 | An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated a… | |
| CVE-2026-84119 | CRITICAL | Patched | 9.6 | 2026-09-01 | Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.… |
| CVE-2026-84121 | CRITICAL | Patched | 9.6 | 2026-09-01 | Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2,… |
| CVE-2026-4813 | NONE | — | 2026-09-01 | A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticated administrators to execute code remotely. The XML/XSLT proces… | |
| CVE-2026-78319 | NONE | — | 2026-09-01 | A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition. An unauthenticated remote attacker could exploit this rac… | |
| CVE-2026-9621 | NONE | — | 2026-09-01 | A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the … | |
| CVE-2026-84149 | NONE | — | 2026-09-01 | This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could… | |
| CVE-2026-84148 | NONE | — | 2026-09-01 | This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit … | |
| CVE-2026-84479 | CRITICAL | 9.1 | 2026-09-01 | WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoM… | |
| CVE-2026-18931 | CRITICAL | 9.1 | 2026-09-01 | Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Retrieve Embedded Sensitive Data. Th… | |
| CVE-2026-51743 | CRITICAL | 9.1 | 2026-09-01 | Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via se… |