Search
454 CVEs · published 2026-09-01 to 2026-09-01
CVEs (454)
Showing 1–25 of 454
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84481 | NONE | — | 2026-09-01 | WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to… | |
| CVE-2026-84642 | NONE | Patched | — | 2026-09-01 | The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this coul… |
| CVE-2026-84637 | NONE | Patched | — | 2026-09-01 | Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment… |
| CVE-2026-84639 | NONE | Patched | — | 2026-09-01 | Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and T… |
| CVE-2026-84640 | NONE | Patched | — | 2026-09-01 | A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thund… |
| CVE-2026-84641 | NONE | Patched | — | 2026-09-01 | A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This … |
| CVE-2026-76851 | NONE | Patched | — | 2026-09-01 | A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance. Insufficient network isola… |
| CVE-2026-83548 | NONE | — | 2026-09-01 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker c… | |
| CVE-2026-19118 | NONE | Patched | — | 2026-09-01 | A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticat… |
| CVE-2026-18730 | NONE | Patched | — | 2026-09-01 | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send craft… |
| CVE-2026-84361 | NONE | Patched | — | 2026-09-01 | Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted co… |
| CVE-2026-84310 | NONE | Patched | — | 2026-09-01 | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes… |
| CVE-2026-84311 | NONE | Patched | — | 2026-09-01 | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.ext… |
| CVE-2026-84309 | NONE | Patched | — | 2026-09-01 | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py T… |
| CVE-2026-77221 | NONE | — | 2026-09-01 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-77222 | NONE | — | 2026-09-01 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-77223 | NONE | — | 2026-09-01 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-84303 | NONE | Patched | — | 2026-09-01 | gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names… |
| CVE-2026-84304 | NONE | Patched | — | 2026-09-01 | gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBu… |
| CVE-2026-84305 | NONE | Patched | — | 2026-09-01 | sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse.format(sql, reindent=True) and sqlformat --reindent route attacker-controlled parenthesi… |
| CVE-2026-51974 | NONE | — | 2026-09-01 | An eval() injection vulnerability in the get_list function in modules/meta_parser.py in lllyasviel Fooocus 2.1.854 through 2.5.5 allows remote attackers to execute arbitrar… | |
| CVE-2026-52022 | NONE | — | 2026-09-01 | An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registration handling components | |
| CVE-2026-52023 | NONE | — | 2026-09-01 | An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_p… | |
| CVE-2026-52111 | NONE | — | 2026-09-01 | An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes authTokenKey | |
| CVE-2026-52131 | NONE | — | 2026-09-01 | llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function. |