Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

144 CVEs · published 2026-09-01 to 2026-09-01, High severity

CVEs (144)

Showing 1–25 of 144

CVE ID Severity Patch CVSS Published Description
CVE-2026-84482 HIGH 8.8 2026-09-01 WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate refe…
CVE-2026-84478 HIGH 7.3 2026-09-01 WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying…
CVE-2026-84476 HIGH 7.5 2026-09-01 WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimi…
CVE-2026-84423 HIGH 7.3 2026-09-01 A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controllers/resource.go of the component upload-resource API. Such manip…
CVE-2026-84208 HIGH 7.5 2026-09-01 AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin's regions.json.php and cities.json.php endpoints. The countr…
CVE-2026-84375 HIGH Patched 7.5 2026-09-01 js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping…
CVE-2026-84374 HIGH Patched 7.5 2026-09-01 Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method res…
CVE-2026-83549 HIGH 7.8 2026-09-01 Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Ma…
CVE-2026-84370 HIGH Patched 8.2 2026-09-01 SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the op…
CVE-2026-84366 HIGH Patched 7.4 2026-09-01 Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-…
CVE-2026-73782 HIGH 8.8 2026-09-01 A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulne…
CVE-2026-73781 HIGH 8.4 2026-09-01 A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a…
CVE-2026-73780 HIGH 8.3 2026-09-01 A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a…
CVE-2026-73779 HIGH 8.2 2026-09-01 Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authenti…
CVE-2026-73778 HIGH 8.1 2026-09-01 A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vuln…
CVE-2026-73777 HIGH 8.1 2026-09-01 Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authenticati…
CVE-2026-73776 HIGH 7.9 2026-09-01 A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation could allow an authenticated malicious actor with admi…
CVE-2026-73775 HIGH 7.7 2026-09-01 Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows a…
CVE-2026-73774 HIGH 7.6 2026-09-01 A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclosure of sensitive information by sending specia…
CVE-2026-73773 HIGH 7.5 2026-09-01 An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to inter…
CVE-2026-73771 HIGH 7.5 2026-09-01 An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker coul…
CVE-2026-73770 HIGH 7.3 2026-09-01 An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outsid…
CVE-2026-73768 HIGH 7.3 2026-09-01 A vulnerability exists in the command line interface of AOS-CX that may allow for improper processing of malformed input. Successful exploitation could result in the execut…
CVE-2026-73767 HIGH 7.2 2026-09-01 Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities results in the ability to ex…
CVE-2026-73766 HIGH 7.2 2026-09-01 Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with administrative privileges to inject arbitrary commands. Su…