Total
396899 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-6924 | 2026-09-08 | N/A | N/A | ||
| A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated. | |||||
| CVE-2026-76969 | 2026-09-08 | N/A | 9.4 CRITICAL | ||
| @sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful exploitation can result in a high impact on availability and integrity of the application. There may also be partial impact to the confidentiality of business data. | |||||
| CVE-2026-17610 | 2026-09-08 | N/A | N/A | ||
| In SiSDK v2026.6.0 and earlier, high network traffic loads can cause a dropped ACK leading to a denial of service. This is only present for EFR32MG24 and EFR32MG26 devices running concurrent multiprotocol Zigbee and Thread. | |||||
| CVE-2026-33389 | 2026-09-08 | N/A | 7.5 HIGH | ||
| An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host's identity, and no option was provided to enable it. A man-in-the-middle attacker positioned between a sensor and a polled device can, during a polling session, impersonate the device and intercept the communication, including the credentials used to access it. The captured credentials can then be replayed to authenticate against the device itself or against other devices sharing the same credentials, allowing the attacker to access and tamper with the device's data and to disrupt its operations. | |||||
| CVE-2026-76963 | 2026-09-08 | N/A | 4.3 MEDIUM | ||
| Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. Successful exploitation could result in exposure of security relevant settings and internal system details, resulting in low impact on confidentiality while integrity and availability remain unaffected. | |||||
| CVE-2026-76971 | 2026-09-08 | N/A | 6.5 MEDIUM | ||
| Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. If processed by the application, this behavior could be combined with XML/XSL processing to enable execution of scripts. Successful exploitation could result in a low impact on the confidentiality, integrity, and availability of the application. | |||||
| CVE-2026-76958 | 2026-09-08 | N/A | 8.5 HIGH | ||
| SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity declarations. Successful exploitation could allow the attacker to read sensitive file contents from the server and expose them through monitoring or logging output, resulting in a high impact on confidentiality. It could also lead to resource exhaustion, causing a low impact on availability. There is no impact on integrity. | |||||
| CVE-2026-13761 | 2026-09-08 | N/A | N/A | ||
| Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping. | |||||
| CVE-2026-65932 | 2026-09-08 | N/A | N/A | ||
| The BT122 module stops advertising after receiving a plaintext 'pause enceryption response' message resulting in a denial of service. See vulnerability B-E2 in the related paper below. | |||||
| CVE-2026-74999 | 1 Roundcube | 1 Webmail | 2026-09-08 | N/A | 5.4 MEDIUM |
| In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS. | |||||
| CVE-2026-74998 | 1 Roundcube | 1 Webmail | 2026-09-08 | N/A | 7.2 HIGH |
| In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing. | |||||
| CVE-2026-85084 | 2026-09-08 | N/A | 6.3 MEDIUM | ||
| Out-of-bounds Write and Improper Validation of Array Index vulnerability in Samsung Open Source TizenFX Samsung/TizenFX allows Overflow Buffers. | |||||
| CVE-2026-49509 | 2026-09-08 | N/A | 4.4 MEDIUM | ||
| Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers. This issue affects rLottie: 25648aef19187b3f87f4d9420b8d761453ad4630. | |||||
| CVE-2026-86313 | 2026-09-08 | N/A | 7.8 HIGH | ||
| Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7. | |||||
| CVE-2026-86315 | 2026-09-08 | N/A | 6.2 MEDIUM | ||
| An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definition whose instance initialization entry count exceeds UINT16_MAX. This issue affects Escargot: 5dc93606abd42b859045add05d704a038e197359. | |||||
| CVE-2026-86314 | 2026-09-08 | N/A | 6.2 MEDIUM | ||
| Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module in which a 32-bit unsigned addition wraps around and bypasses the bounds check. This issue affects Walrus: ff3bf5ff5c4878f8e5572c9593d303f6bc997443. | |||||
| CVE-2026-85147 | 2026-09-08 | N/A | 7.5 HIGH | ||
| SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication. | |||||
| CVE-2026-85148 | 2026-09-08 | N/A | 9.8 CRITICAL | ||
| SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts. | |||||
| CVE-2026-84022 | 2026-09-08 | N/A | 6.8 MEDIUM | ||
| The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before outputting them in HTML attributes, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page. | |||||
| CVE-2026-75793 | 2026-09-08 | N/A | 6.5 MEDIUM | ||
| The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled. | |||||
