Total
396887 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-85157 | 2026-09-08 | N/A | 5.3 MEDIUM | ||
| WWBN AVideo contains a broken access control vulnerability in the unauthenticated feed/index.php endpoint that disables per-video visibility checks when a program_id parameter is supplied. Attackers can enumerate playlist identifiers and retrieve unlisted and group-restricted videos by requesting the RSS feed with any visible playlist id, including empty playlists that return the entire site's hidden video catalogue. | |||||
| CVE-2026-85614 | 2026-09-08 | N/A | 8.6 HIGH | ||
| OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled URL parameter with no private IP filtering or DNS-rebinding protection. Attackers can make the OpenPanel server issue requests to internal services, localhost, and cloud metadata endpoints, reading internal HTTP response titles, headers, status codes, and SSL certificate information. | |||||
| CVE-2026-84695 | 2026-09-08 | N/A | 8.7 HIGH | ||
| BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed through the image gallery API without content-type validation or CSP headers. | |||||
| CVE-2026-85164 | 2026-09-08 | N/A | 7.1 HIGH | ||
| WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set_api_userImages API endpoint that fails to validate profileImg and backgroundImg URLs before fetching them. Authenticated API clients can supply internal URLs to fetch cloud metadata or internal services, with responses written to publicly accessible web paths for retrieval. | |||||
| CVE-2026-84477 | 2026-09-08 | N/A | 5.4 MEDIUM | ||
| AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts. Unauthenticated attackers can access remindMe.php to execute stored XSS payloads in victim browsers without requiring authentication. | |||||
| CVE-2026-82879 | 2026-09-08 | N/A | 6.3 MEDIUM | ||
| DataEase before 2.10.26 contains multiple access control defects in the sharing link module. Tickets are not bound to the target share UUID, so a valid ticket issued for one share can be reused against another (ShareTicketManage.validateTicket / POST /de2api/share/proxyInfo). The POST /de2api/share/validate endpoint issues a LinkToken after password verification without requiring a ticket, bypassing the 'ticket mandatory' policy. Additionally, the ticket create and delete endpoints (POST /de2api/ticket/saveTicket, POST /de2api/ticket/delTicket) lack share-ownership checks, allowing an authenticated user who knows another user's ticket to modify, rebind, or delete it (denial of service), and GET /de2api/share/queryRelationByUserId/{uid} allows authenticated users to enumerate other users' share mappings. | |||||
| CVE-2026-82882 | 2026-09-08 | N/A | 8.8 HIGH | ||
| Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitrary project, environment, and application parameters to retrieve plaintext super-admin JWT tokens for full platform control. | |||||
| CVE-2026-84193 | 2026-09-08 | N/A | N/A | ||
| LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer descriptions, VRF names, process information, and SLA tags. Attackers with device management access or network access to enroll a rogue SNMP device can inject malicious JavaScript that executes when admins view affected routing and device pages, enabling credential theft and CSRF token exfiltration. | |||||
| CVE-2026-85388 | 2026-09-08 | N/A | 8.1 HIGH | ||
| Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolean-based blind SQL injection techniques to extract sensitive database content including password hashes from other tenants. This is an incomplete fix for CVE-2026-25947. | |||||
| CVE-2026-84476 | 2026-09-08 | N/A | 7.5 HIGH | ||
| WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can rotate the header value per request to bypass login rate limiting and perform unlimited credential guessing attacks. | |||||
| CVE-2023-54391 | 2026-09-08 | N/A | 9.8 CRITICAL | ||
| Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life. | |||||
| CVE-2026-86716 | 2026-09-08 | 7.5 HIGH | 7.3 HIGH | ||
| A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_comments of the file src/mjs_tok.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. | |||||
| CVE-2026-70579 | 2026-09-08 | N/A | 7.5 HIGH | ||
| Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-69562 | 2026-09-08 | N/A | 6.5 MEDIUM | ||
| Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-69541 | 2026-09-08 | N/A | 7.8 HIGH | ||
| Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-69432 | 2026-09-08 | N/A | 7.8 HIGH | ||
| Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-69395 | 2026-09-08 | N/A | 6.5 MEDIUM | ||
| Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network. | |||||
| CVE-2026-69376 | 2026-09-08 | N/A | 5.5 MEDIUM | ||
| Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-69325 | 2026-09-08 | N/A | 8.1 HIGH | ||
| Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69304 | 2026-09-08 | N/A | 5.9 MEDIUM | ||
| Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |||||
