Search
565 CVEs · published 2026-09-24 to 2026-09-24
CVEs (565, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 565 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61732 | CRITICAL | 10.0 | 2026-09-24 | Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of agent reconnaissance against target services — into… | |
| CVE-2026-97359 | CRITICAL | 10.0 | 2026-09-24 | HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code exec… | |
| CVE-2026-97360 | CRITICAL | 10.0 | 2026-09-24 | HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete file… | |
| CVE-2026-93425 | CRITICAL | Patched | 9.9 | 2026-09-24 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from… |
| CVE-2026-19072 | CRITICAL | 9.9 | 2026-09-24 | Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_co… | |
| CVE-2026-89078 | CRITICAL | Patched | 9.9 | 2026-09-24 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions coul… |
| CVE-2026-93577 | CRITICAL | Patched | 9.9 | 2026-09-24 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions coul… |
| CVE-2026-13249 | CRITICAL | 9.8 | 2026-09-24 | An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040,… | |
| CVE-2026-12227 | CRITICAL | 9.8 | 2026-09-24 | The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` paramete… | |
| CVE-2026-78308 | CRITICAL | Patched | 9.8 | 2026-09-24 | Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022. |
| CVE-2026-96891 | CRITICAL | 9.8 | 2026-09-24 | A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the … | |
| CVE-2026-18467 | CRITICAL | 9.8 | 2026-09-24 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.3. The 5.0.3 patch introd… | |
| CVE-2026-95699 | CRITICAL | 9.6 | 2026-09-24 | Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data an… | |
| CVE-2026-81549 | CRITICAL | 9.6 | 2026-09-24 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header. | |
| CVE-2026-93291 | CRITICAL | 9.4 | 2026-09-24 | Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code. | |
| CVE-2026-86860 | NONE | Patched | — | 2026-09-24 | ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, … |
| CVE-2026-13016 | NONE | Patched | — | 2026-09-24 | ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certa… |
| CVE-2026-61741 | CRITICAL | 9.3 | 2026-09-24 | http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.x… | |
| CVE-2026-61742 | NONE | — | 2026-09-24 | DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose an unauthenticated HTTP MCP endpoint when started w… | |
| CVE-2026-61604 | NONE | Patched | — | 2026-09-24 | The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds module moved funds from an address that was resolved f… |
| CVE-2026-91187 | NONE | Patched | — | 2026-09-24 | Improper Verification of Cryptographic Signature vulnerability in dashbit nimble_zta allows an unauthenticated remote attacker to authenticate as an arbitrary Cloudflare se… |
| CVE-2026-97404 | NONE | Patched | — | 2026-09-24 | In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticated remote att… |
| CVE-2026-90481 | NONE | Patched | — | 2026-09-24 | In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel. |
| CVE-2026-79766 | CRITICAL | Patched | 9.1 | 2026-09-24 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.1 until 2.5.1, an authenticated Termix administrator … |
| CVE-2026-78312 | CRITICAL | Patched | 9.1 | 2026-09-24 | Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. |