Search
454 CVEs · published 2026-09-01 to 2026-09-01
CVEs (454)
Showing 1–25 of 454
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-84483 | MEDIUM | 5.3 | 2026-09-01 | WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens … | |
| CVE-2026-84482 | HIGH | 8.8 | 2026-09-01 | WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate refe… | |
| CVE-2026-84481 | NONE | — | 2026-09-01 | WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to… | |
| CVE-2026-84480 | CRITICAL | 9.8 | 2026-09-01 | WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefi… | |
| CVE-2026-84479 | CRITICAL | 9.1 | 2026-09-01 | WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoM… | |
| CVE-2026-84478 | HIGH | 7.3 | 2026-09-01 | WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying… | |
| CVE-2026-84477 | MEDIUM | 5.4 | 2026-09-01 | AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts. Unauthent… | |
| CVE-2026-84476 | HIGH | 7.5 | 2026-09-01 | WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimi… | |
| CVE-2026-84423 | HIGH | 7.3 | 2026-09-01 | A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controllers/resource.go of the component upload-resource API. Such manip… | |
| CVE-2026-84208 | HIGH | 7.5 | 2026-09-01 | AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin's regions.json.php and cities.json.php endpoints. The countr… | |
| CVE-2026-84642 | NONE | Patched | — | 2026-09-01 | The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this coul… |
| CVE-2026-84641 | NONE | Patched | — | 2026-09-01 | A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This … |
| CVE-2026-84640 | NONE | Patched | — | 2026-09-01 | A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thund… |
| CVE-2026-84639 | NONE | Patched | — | 2026-09-01 | Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and T… |
| CVE-2026-84637 | NONE | Patched | — | 2026-09-01 | Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment… |
| CVE-2026-84375 | HIGH | Patched | 7.5 | 2026-09-01 | js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping… |
| CVE-2026-84374 | HIGH | Patched | 7.5 | 2026-09-01 | Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method res… |
| CVE-2026-84373 | MEDIUM | Patched | 5.9 | 2026-09-01 | Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 and 5.0.0-rc.2, the public mockerPlugin and standalone interceptorPlugin exports in packages/mocker/s… |
| CVE-2026-84372 | CRITICAL | Patched | 9.8 | 2026-09-01 | Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replicatio… |
| CVE-2026-84289 | MEDIUM | 4.3 | 2026-09-01 | A vulnerability was found in NousResearch hermes-agent up to 0.18.2. This vulnerability affects the function list_tools of the file tools/mcp_tool.py of the component MCP T… | |
| CVE-2026-84288 | MEDIUM | 4.3 | 2026-09-01 | A vulnerability has been found in NousResearch hermes-agent up to 0.18.2. This affects the function HermesACPAgent.prompt of the file acp_adapter/session.py of the componen… | |
| CVE-2026-83549 | HIGH | 7.8 | 2026-09-01 | Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Ma… | |
| CVE-2026-83548 | NONE | — | 2026-09-01 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker c… | |
| CVE-2026-76851 | NONE | Patched | — | 2026-09-01 | A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance. Insufficient network isola… |
| CVE-2026-75604 | CRITICAL | Patched | 9.0 | 2026-09-01 | Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without C… |