Search
454 CVEs · published 2026-09-01 to 2026-09-01
CVEs (454)
Showing 1–25 of 454
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-19820 | NONE | — | 2026-09-01 | A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows OS system files during a b… | |
| CVE-2026-18743 | LOW | 2.5 | 2026-09-01 | A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory… | |
| CVE-2026-48932 | LOW | 3.7 | 2026-09-01 | A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` he… | |
| CVE-2026-65643 | NONE | — | 2026-09-01 | Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root. | |
| CVE-2026-67394 | NONE | Patched | — | 2026-09-01 | A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 an… |
| CVE-2026-67395 | MEDIUM | 5.9 | 2026-09-01 | A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation of file path parameters. By leveraging directory … | |
| CVE-2026-74837 | NONE | Patched | — | 2026-09-01 | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort… |
| CVE-2026-75865 | CRITICAL | 9.8 | 2026-09-01 | The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing… | |
| CVE-2026-77856 | NONE | Patched | — | 2026-09-01 | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort… |
| CVE-2026-77950 | NONE | Patched | — | 2026-09-01 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to receive unredacted internal e… |
| CVE-2026-82730 | NONE | Patched | — | 2026-09-01 | Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute values that Ash field policies denied. When a field… |
| CVE-2026-82731 | NONE | Patched | — | 2026-09-01 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an attacker who controls a path-parameter value to redirect a generat… |
| CVE-2026-82732 | NONE | Patched | — | 2026-09-01 | Improper Input Validation vulnerability in ash-project ash_typescript allows a remote attacker to submit argument values outside a declared allowlist or bound on typed-cont… |
| CVE-2026-82733 | NONE | Patched | — | 2026-09-01 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to read internal application dat… |
| CVE-2026-19032 | MEDIUM | Patched | 5.3 | 2026-09-01 | jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.dese… |
| CVE-2026-82734 | NONE | Patched | — | 2026-09-01 | Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to submit a non-finite decimal value that bypasses numeric bounds con… |
| CVE-2026-82735 | NONE | Patched | — | 2026-09-01 | Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to force an expensive regular expression to run on input that a length constraint shou… |
| CVE-2026-82736 | NONE | Patched | — | 2026-09-01 | Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store a case-insensitive string value that violates its length or m… |
| CVE-2026-82737 | NONE | Patched | — | 2026-09-01 | Integer Overflow or Wraparound vulnerability in ash-project ash lets an attacker corrupt a stored vector and crash later reads of it by submitting a vector with more than 6… |
| CVE-2026-82738 | NONE | Patched | — | 2026-09-01 | Improper Input Validation vulnerability in ash-project ash allows an attacker to persistently deny reads of a record by storing a non-version-7 UUID in an Ash.Type.UUIDv7 a… |
| CVE-2026-82739 | NONE | Patched | — | 2026-09-01 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash discloses the stored value of a confirmed field to an actor who fails its conf… |
| CVE-2026-82740 | NONE | Patched | — | 2026-09-01 | Improper Input Validation vulnerability in ash-project ash fails to enforce the outer array constraints on a doubly-nested {:array, {:array, type}} attribute, letting inval… |
| CVE-2026-82741 | NONE | Patched | — | 2026-09-01 | Improper Validation of Specified Type of Input vulnerability in ash-project ash lets an attacker confuse the stored type tag of an Ash.Type.Union value that uses storage: :… |
| CVE-2026-82742 | NONE | Patched | — | 2026-09-01 | Uncontrolled Resource Consumption vulnerability in ash-project ash lets an attacker exhaust node memory by matching a filter that spans multiple to-many relationships in me… |
| CVE-2026-82743 | NONE | Patched | — | 2026-09-01 | Uncontrolled Resource Consumption vulnerability in ash-project ash lets a slow asynchronous read spin a scheduler thread at full CPU while the framework waits for it. Ash.… |