Search
144 CVEs · published 2026-09-01 to 2026-09-01, High severity
CVEs (144)
Showing 1–25 of 144
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-84482 | HIGH | 8.8 | 2026-09-01 | WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate refe… | |
| CVE-2026-84478 | HIGH | 7.3 | 2026-09-01 | WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying… | |
| CVE-2026-84476 | HIGH | 7.5 | 2026-09-01 | WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimi… | |
| CVE-2026-84423 | HIGH | 7.3 | 2026-09-01 | A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controllers/resource.go of the component upload-resource API. Such manip… | |
| CVE-2026-84208 | HIGH | 7.5 | 2026-09-01 | AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin's regions.json.php and cities.json.php endpoints. The countr… | |
| CVE-2026-84375 | HIGH | Patched | 7.5 | 2026-09-01 | js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping… |
| CVE-2026-84374 | HIGH | Patched | 7.5 | 2026-09-01 | Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method res… |
| CVE-2026-83549 | HIGH | 7.8 | 2026-09-01 | Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Ma… | |
| CVE-2026-84370 | HIGH | Patched | 8.2 | 2026-09-01 | SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the op… |
| CVE-2026-84366 | HIGH | Patched | 7.4 | 2026-09-01 | Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-… |
| CVE-2026-73782 | HIGH | 8.8 | 2026-09-01 | A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulne… | |
| CVE-2026-73781 | HIGH | 8.4 | 2026-09-01 | A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a… | |
| CVE-2026-73780 | HIGH | 8.3 | 2026-09-01 | A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a… | |
| CVE-2026-73779 | HIGH | 8.2 | 2026-09-01 | Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authenti… | |
| CVE-2026-73778 | HIGH | 8.1 | 2026-09-01 | A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vuln… | |
| CVE-2026-73777 | HIGH | 8.1 | 2026-09-01 | Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authenticati… | |
| CVE-2026-73776 | HIGH | 7.9 | 2026-09-01 | A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation could allow an authenticated malicious actor with admi… | |
| CVE-2026-73775 | HIGH | 7.7 | 2026-09-01 | Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows a… | |
| CVE-2026-73774 | HIGH | 7.6 | 2026-09-01 | A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclosure of sensitive information by sending specia… | |
| CVE-2026-73773 | HIGH | 7.5 | 2026-09-01 | An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to inter… | |
| CVE-2026-73771 | HIGH | 7.5 | 2026-09-01 | An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker coul… | |
| CVE-2026-73770 | HIGH | 7.3 | 2026-09-01 | An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outsid… | |
| CVE-2026-73768 | HIGH | 7.3 | 2026-09-01 | A vulnerability exists in the command line interface of AOS-CX that may allow for improper processing of malformed input. Successful exploitation could result in the execut… | |
| CVE-2026-73767 | HIGH | 7.2 | 2026-09-01 | Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities results in the ability to ex… | |
| CVE-2026-73766 | HIGH | 7.2 | 2026-09-01 | Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with administrative privileges to inject arbitrary commands. Su… |