Search
18 CVEs · published 2026-09-24 to 2026-09-24, Critical severity
CVEs (18)
Showing 1–18 of 18
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-95699 | CRITICAL | 9.6 | 2026-09-24 | Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data an… | |
| CVE-2026-93291 | CRITICAL | 9.4 | 2026-09-24 | Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code. | |
| CVE-2026-13249 | CRITICAL | 9.8 | 2026-09-24 | An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040,… | |
| CVE-2026-61741 | CRITICAL | 9.3 | 2026-09-24 | http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.x… | |
| CVE-2026-61732 | CRITICAL | 10.0 | 2026-09-24 | Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of agent reconnaissance against target services — into… | |
| CVE-2026-79766 | CRITICAL | Patched | 9.1 | 2026-09-24 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.1 until 2.5.1, an authenticated Termix administrator … |
| CVE-2026-93425 | CRITICAL | Patched | 9.9 | 2026-09-24 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from… |
| CVE-2026-81549 | CRITICAL | 9.6 | 2026-09-24 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header. | |
| CVE-2026-97360 | CRITICAL | 10.0 | 2026-09-24 | HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete file… | |
| CVE-2026-97359 | CRITICAL | 10.0 | 2026-09-24 | HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code exec… | |
| CVE-2026-19072 | CRITICAL | 9.9 | 2026-09-24 | Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_co… | |
| CVE-2026-12227 | CRITICAL | 9.8 | 2026-09-24 | The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` paramete… | |
| CVE-2026-78312 | CRITICAL | Patched | 9.1 | 2026-09-24 | Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. |
| CVE-2026-78308 | CRITICAL | Patched | 9.8 | 2026-09-24 | Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022. |
| CVE-2026-96891 | CRITICAL | 9.8 | 2026-09-24 | A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the … | |
| CVE-2026-18467 | CRITICAL | 9.8 | 2026-09-24 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.3. The 5.0.3 patch introd… | |
| CVE-2026-93577 | CRITICAL | Patched | 9.9 | 2026-09-24 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions coul… |
| CVE-2026-89078 | CRITICAL | Patched | 9.9 | 2026-09-24 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions coul… |