Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

121 CVEs · published 2026-09-01 to 2026-09-01, Medium severity

CVEs (121)

Showing 1–25 of 121

CVE ID Severity Patch CVSS Published Description
CVE-2026-84483 MEDIUM 5.3 2026-09-01 WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens …
CVE-2026-84477 MEDIUM 5.4 2026-09-01 AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts. Unauthent…
CVE-2026-84373 MEDIUM Patched 5.9 2026-09-01 Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 and 5.0.0-rc.2, the public mockerPlugin and standalone interceptorPlugin exports in packages/mocker/s…
CVE-2026-84289 MEDIUM 4.3 2026-09-01 A vulnerability was found in NousResearch hermes-agent up to 0.18.2. This vulnerability affects the function list_tools of the file tools/mcp_tool.py of the component MCP T…
CVE-2026-84288 MEDIUM 4.3 2026-09-01 A vulnerability has been found in NousResearch hermes-agent up to 0.18.2. This affects the function HermesACPAgent.prompt of the file acp_adapter/session.py of the componen…
CVE-2026-84470 MEDIUM 6.4 2026-09-01 A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_gro…
CVE-2026-84371 MEDIUM Patched 5.4 2026-09-01 ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.1…
CVE-2026-84369 MEDIUM Patched 6.1 2026-09-01 SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the op…
CVE-2026-84365 MEDIUM Patched 6.5 2026-09-01 Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix released for CVE-2026-39408 does not cover every tr…
CVE-2026-84364 MEDIUM Patched 5.3 2026-09-01 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, when parseBody() expands dot-separated form field names into nested o…
CVE-2026-84363 MEDIUM Patched 5.9 2026-09-01 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, Hono's query helpers treat a question mark after a literal hash fragm…
CVE-2026-84287 MEDIUM 4.3 2026-09-01 A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is some unknown functionality of the file gateway/platforms/api_server.py of the component…
CVE-2026-73783 MEDIUM 4.9 2026-09-01 Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service conditi…
CVE-2026-73772 MEDIUM 6.5 2026-09-01 Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted pack…
CVE-2026-73762 MEDIUM 6.6 2026-09-01 A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases this could enable un…
CVE-2026-73761 MEDIUM 6.5 2026-09-01 An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially cra…
CVE-2026-73760 MEDIUM 6.5 2026-09-01 An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the web-based …
CVE-2026-73759 MEDIUM 6.5 2026-09-01 Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful ex…
CVE-2026-73758 MEDIUM 6.5 2026-09-01 A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the st…
CVE-2026-73757 MEDIUM 6.4 2026-09-01 A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A succe…
CVE-2026-73756 MEDIUM 5.9 2026-09-01 A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploi…
CVE-2026-73755 MEDIUM 5.7 2026-09-01 A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a require…
CVE-2026-73754 MEDIUM 5.3 2026-09-01 Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could allow an authenticated user to disrupt the normal operation o…
CVE-2026-73524 MEDIUM Patched 6.1 2026-09-01 Cypht before 2.12.2 contains a cross-site scripting vulnerability in the contacts module that allows remote attackers to execute arbitrary script content by embedding malic…
CVE-2026-63435 MEDIUM Patched 5.3 2026-09-01 Mail is an internet library for Ruby designed to handle email generation, parsing, and sending. Prior to 2.9.1, Mail::Utilities.q_value_decode and Mail::Utilities.b_value_d…