Total
396929 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-85106 | 2026-09-05 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A vulnerability has been found in NousResearch hermes-agent 0.18.0. This affects the function fetchLinkTitle of the file apps/desktop/src/app/artifacts/index.tsx of the component Link Title Fetch. Such manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-84847 | 2026-09-05 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions. | |||||
| CVE-2026-84812 | 2026-09-05 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions. | |||||
| CVE-2026-84774 | 2026-09-05 | N/A | 6.1 MEDIUM | ||
| Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions. | |||||
| CVE-2026-84766 | 2026-09-05 | N/A | 5.9 MEDIUM | ||
| Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions. | |||||
| CVE-2026-84758 | 2026-09-05 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions. | |||||
| CVE-2026-84753 | 2026-09-05 | N/A | 9.8 CRITICAL | ||
| Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. | |||||
| CVE-2026-81773 | 2026-09-05 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | |||||
| CVE-2026-81281 | 2026-09-05 | N/A | 6.5 MEDIUM | ||
| Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions. | |||||
| CVE-2026-75036 | 2026-09-05 | N/A | N/A | ||
| A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user who can supply bundle content to a repository referenced by a `GitRepo` resource can cause the Fleet controller to: - Disclose cluster metadata available to the templating context. - Reveal information about hosts reachable from the controller's network position. Because the disclosure channel is name resolution, it may remain effective in environments where outbound traffic is otherwise restricted. The disclosed information is limited to values exposed to the Fleet templating context and to name resolution results. Integrity and availability of managed clusters are not affected. This issue affects Fleet: from 0.12.0 before 0.12.19, from 0.13.0 before 0.13.15, from 0.14.0 before 0.14.10, from 0.15.0 before 0.15.6, and from 0.16.0 before 0.16.1. | |||||
| CVE-2026-85030 | 2026-09-05 | 2.6 LOW | 3.7 LOW | ||
| A vulnerability has been found in HKUDS AI-Trader up to d03ff6c056b32ced735adf7c19ed8175adb1c8df. The affected element is an unknown function of the file service/server/routes_agent.py of the component selfRegister API Endpoint. Such manipulation of the argument initial_balance leads to business logic errors. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. profit_percent_for_display() divides by INITIAL_CAPITAL + deposited, and challenge scoring's return_pct also normalises against the attacker-inflated starting_cash. So an inflated initial_balance does not yield artificial percent returns - it inflates the absolute cash/equity column only, which is a cosmetic/leaderboard-gaming concern in a simulated game. | |||||
| CVE-2026-84886 | 2026-09-05 | 5.0 MEDIUM | 5.3 MEDIUM | ||
| A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affected by this vulnerability is the function ImageData of the file gui_agents/s1/utils/ocr_server.py of the component OCR HTTP API. Executing a manipulation of the argument img_bytes can lead to resource consumption. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-84841 | 2026-09-05 | 7.5 HIGH | 7.3 HIGH | ||
| A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enforcement of server-side security. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.5.1 is able to resolve this issue. It is recommended to upgrade the affected component. | |||||
| CVE-2026-74769 | 2026-09-05 | N/A | 6.5 MEDIUM | ||
| Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API. A low privileged remote attacker could potentially exploit this vulnerability, leading to Protection mechanism bypass. | |||||
| CVE-2026-66786 | 2026-09-05 | N/A | 9.1 CRITICAL | ||
| A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdown hooks, leading to remote code execution as root on the gateway node. | |||||
| CVE-2026-61884 | 2026-09-04 | N/A | 9.8 CRITICAL | ||
| The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker with network access to such a unit can reach full device controls, including power relay management, device reboot, remote access service configuration, and network settings, which could allow disruption of connected infrastructure or physical damage to equipment. | |||||
| CVE-2026-55985 | 2026-09-04 | N/A | 4.3 MEDIUM | ||
| The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network. | |||||
| CVE-2025-70082 | 1 Lantronix | 4 Eds3008ps1ns, Eds3008ps1ns Firmware, Eds3016ps1ns and 1 more | 2026-09-04 | N/A | 2.7 LOW |
| The administrator password can be changed without knowledge of the current password. When chained with an authentication bypass vulnerability, this issue may allow unauthenticated attackers to modify the administrator password. | |||||
| CVE-2025-67041 | 1 Lantronix | 4 Eds3008ps1ns, Eds3008ps1ns Firmware, Eds3016ps1ns and 1 more | 2026-09-04 | N/A | 7.2 HIGH |
| An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly sanitized. This can be exploited to escape from the original command and execute an arbitrary one with root privileges. | |||||
| CVE-2025-67039 | 1 Lantronix | 4 Eds3008ps1ns, Eds3008ps1ns Firmware, Eds3016ps1ns and 1 more | 2026-09-04 | N/A | 9.8 CRITICAL |
| An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to the URL and by sending an Authorization header that uses "admin" as the username. | |||||
