Search
121 CVEs · published 2026-09-01 to 2026-09-01, Medium severity
CVEs (121)
Showing 1–25 of 121
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-84483 | MEDIUM | 5.3 | 2026-09-01 | WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens … | |
| CVE-2026-84477 | MEDIUM | 5.4 | 2026-09-01 | AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts. Unauthent… | |
| CVE-2026-84373 | MEDIUM | Patched | 5.9 | 2026-09-01 | Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 and 5.0.0-rc.2, the public mockerPlugin and standalone interceptorPlugin exports in packages/mocker/s… |
| CVE-2026-84289 | MEDIUM | 4.3 | 2026-09-01 | A vulnerability was found in NousResearch hermes-agent up to 0.18.2. This vulnerability affects the function list_tools of the file tools/mcp_tool.py of the component MCP T… | |
| CVE-2026-84288 | MEDIUM | 4.3 | 2026-09-01 | A vulnerability has been found in NousResearch hermes-agent up to 0.18.2. This affects the function HermesACPAgent.prompt of the file acp_adapter/session.py of the componen… | |
| CVE-2026-84470 | MEDIUM | 6.4 | 2026-09-01 | A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_gro… | |
| CVE-2026-84371 | MEDIUM | Patched | 5.4 | 2026-09-01 | ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.1… |
| CVE-2026-84369 | MEDIUM | Patched | 6.1 | 2026-09-01 | SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the op… |
| CVE-2026-84365 | MEDIUM | Patched | 6.5 | 2026-09-01 | Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix released for CVE-2026-39408 does not cover every tr… |
| CVE-2026-84364 | MEDIUM | Patched | 5.3 | 2026-09-01 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, when parseBody() expands dot-separated form field names into nested o… |
| CVE-2026-84363 | MEDIUM | Patched | 5.9 | 2026-09-01 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, Hono's query helpers treat a question mark after a literal hash fragm… |
| CVE-2026-84287 | MEDIUM | 4.3 | 2026-09-01 | A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is some unknown functionality of the file gateway/platforms/api_server.py of the component… | |
| CVE-2026-73783 | MEDIUM | 4.9 | 2026-09-01 | Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service conditi… | |
| CVE-2026-73772 | MEDIUM | 6.5 | 2026-09-01 | Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted pack… | |
| CVE-2026-73762 | MEDIUM | 6.6 | 2026-09-01 | A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases this could enable un… | |
| CVE-2026-73761 | MEDIUM | 6.5 | 2026-09-01 | An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially cra… | |
| CVE-2026-73760 | MEDIUM | 6.5 | 2026-09-01 | An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the web-based … | |
| CVE-2026-73759 | MEDIUM | 6.5 | 2026-09-01 | Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful ex… | |
| CVE-2026-73758 | MEDIUM | 6.5 | 2026-09-01 | A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the st… | |
| CVE-2026-73757 | MEDIUM | 6.4 | 2026-09-01 | A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A succe… | |
| CVE-2026-73756 | MEDIUM | 5.9 | 2026-09-01 | A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploi… | |
| CVE-2026-73755 | MEDIUM | 5.7 | 2026-09-01 | A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a require… | |
| CVE-2026-73754 | MEDIUM | 5.3 | 2026-09-01 | Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could allow an authenticated user to disrupt the normal operation o… | |
| CVE-2026-73524 | MEDIUM | Patched | 6.1 | 2026-09-01 | Cypht before 2.12.2 contains a cross-site scripting vulnerability in the contacts module that allows remote attackers to execute arbitrary script content by embedding malic… |
| CVE-2026-63435 | MEDIUM | Patched | 5.3 | 2026-09-01 | Mail is an internet library for Ruby designed to handle email generation, parsing, and sending. Prior to 2.9.1, Mail::Utilities.q_value_decode and Mail::Utilities.b_value_d… |