Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

454 CVEs · published 2026-09-01 to 2026-09-01

CVEs (454)

Showing 1–25 of 454

CVE ID Severity Patch CVSS Published Description
CVE-2026-19820 NONE — 2026-09-01 A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows OS system files during a b…
CVE-2026-18743 LOW 2.5 2026-09-01 A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory…
CVE-2026-48932 LOW 3.7 2026-09-01 A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` he…
CVE-2026-65643 NONE — 2026-09-01 Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
CVE-2026-67394 NONE Patched — 2026-09-01 A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 an…
CVE-2026-67395 MEDIUM 5.9 2026-09-01 A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation of file path parameters. By leveraging directory …
CVE-2026-74837 NONE Patched — 2026-09-01 Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort…
CVE-2026-75865 CRITICAL 9.8 2026-09-01 The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing…
CVE-2026-77856 NONE Patched — 2026-09-01 Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort…
CVE-2026-77950 NONE Patched — 2026-09-01 Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to receive unredacted internal e…
CVE-2026-82730 NONE Patched — 2026-09-01 Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute values that Ash field policies denied. When a field…
CVE-2026-82731 NONE Patched — 2026-09-01 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an attacker who controls a path-parameter value to redirect a generat…
CVE-2026-82732 NONE Patched — 2026-09-01 Improper Input Validation vulnerability in ash-project ash_typescript allows a remote attacker to submit argument values outside a declared allowlist or bound on typed-cont…
CVE-2026-82733 NONE Patched — 2026-09-01 Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to read internal application dat…
CVE-2026-19032 MEDIUM Patched 5.3 2026-09-01 jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.dese…
CVE-2026-82734 NONE Patched — 2026-09-01 Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to submit a non-finite decimal value that bypasses numeric bounds con…
CVE-2026-82735 NONE Patched — 2026-09-01 Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to force an expensive regular expression to run on input that a length constraint shou…
CVE-2026-82736 NONE Patched — 2026-09-01 Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store a case-insensitive string value that violates its length or m…
CVE-2026-82737 NONE Patched — 2026-09-01 Integer Overflow or Wraparound vulnerability in ash-project ash lets an attacker corrupt a stored vector and crash later reads of it by submitting a vector with more than 6…
CVE-2026-82738 NONE Patched — 2026-09-01 Improper Input Validation vulnerability in ash-project ash allows an attacker to persistently deny reads of a record by storing a non-version-7 UUID in an Ash.Type.UUIDv7 a…
CVE-2026-82739 NONE Patched — 2026-09-01 Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash discloses the stored value of a confirmed field to an actor who fails its conf…
CVE-2026-82740 NONE Patched — 2026-09-01 Improper Input Validation vulnerability in ash-project ash fails to enforce the outer array constraints on a doubly-nested {:array, {:array, type}} attribute, letting inval…
CVE-2026-82741 NONE Patched — 2026-09-01 Improper Validation of Specified Type of Input vulnerability in ash-project ash lets an attacker confuse the stored type tag of an Ash.Type.Union value that uses storage: :…
CVE-2026-82742 NONE Patched — 2026-09-01 Uncontrolled Resource Consumption vulnerability in ash-project ash lets an attacker exhaust node memory by matching a filter that spans multiple to-many relationships in me…
CVE-2026-82743 NONE Patched — 2026-09-01 Uncontrolled Resource Consumption vulnerability in ash-project ash lets a slow asynchronous read spin a scheduler thread at full CPU while the framework waits for it. Ash.…