Total
396943 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-84794 | 2026-09-04 | N/A | 7.1 HIGH | ||
| Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users' folders and force deletion of conflicting files, allowing unauthorized asset deletion and replacement. | |||||
| CVE-2026-84780 | 2026-09-04 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions. | |||||
| CVE-2026-84764 | 2026-09-04 | N/A | 8.8 HIGH | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions. | |||||
| CVE-2026-84441 | 2026-09-04 | 7.5 HIGH | 7.3 HIGH | ||
| A security vulnerability has been detected in Piwigo up to 16.3.0. Affected by this issue is some unknown functionality of the file i.php of the component Image Derivative Handler. The manipulation leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. | |||||
| CVE-2026-84427 | 2026-09-04 | 4.0 MEDIUM | 4.3 MEDIUM | ||
| A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affected is an unknown function of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-84287 | 2026-09-04 | 4.0 MEDIUM | 4.3 MEDIUM | ||
| A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is some unknown functionality of the file gateway/platforms/api_server.py of the component Session Chat Interface. This manipulation causes denial of service. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-84269 | 2026-09-04 | N/A | 6.5 MEDIUM | ||
| A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the intended boundaries. This issue allows a malicious server to overflow a heap buffer and crash the gvfsd-afp process, resulting in a denial of service. | |||||
| CVE-2026-81775 | 2026-09-04 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions. | |||||
| CVE-2026-81769 | 2026-09-04 | N/A | 8.8 HIGH | ||
| Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1. | |||||
| CVE-2026-81286 | 2026-09-04 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions. | |||||
| CVE-2026-3850 | 2026-09-04 | N/A | 6.4 MEDIUM | ||
| The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb_contact_form` shortcode in all versions up to, and including, 4.27.6. This is due to the `redirect_url` attribute being sanitized with `esc_attr()` instead of `esc_url()` before being rendered into the `data-redirect_url` HTML data attribute. Additionally, `redirect_url` is absent from the hardcoded `$url_options` array in `class-et-builder-element.php`, so it does not receive `esc_url_raw()` sanitization during shortcode parsing. After a successful form submission, client-side JavaScript reads this data attribute and passes it directly to `window.location.href`, executing arbitrary JavaScript from a `javascript:` URI. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that execute whenever a user submits the contact form. | |||||
| CVE-2026-16493 | 2026-09-04 | N/A | 7.8 HIGH | ||
| A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator before user-supplied URLs when installing collections from git sources. An attacker who provides a crafted collection source URI containing git argument injection payloads can achieve arbitrary command execution when a user runs 'ansible-galaxy collection install' with the malicious source. This is an incomplete fix for CVE-2026-11332, which hardened the role install path but missed the equivalent collection install code path. | |||||
| CVE-2026-14982 | 2026-09-04 | N/A | 8.1 HIGH | ||
| The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The two-stage exploit requires a first request to the file.save task to persist the path-traversal string into file metadata, followed by a second request to the file.delete task to trigger the unlink call — both endpoints lack capability checks and nonce enforcement. | |||||
| CVE-2026-84233 | 2026-09-04 | N/A | 7.0 HIGH | ||
| A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability. | |||||
| CVE-2026-84110 | 2026-09-04 | 5.0 MEDIUM | 5.3 MEDIUM | ||
| A vulnerability was detected in Releasit Releasit COD Form & Upsells v1. This vulnerability affects unknown code of the component OTP Validation. The manipulation results in client-side enforcement of server-side security. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version v2 is able to resolve this issue. The affected component should be upgraded. | |||||
| CVE-2025-5459 | 1 Puppet | 1 Puppet Enterprise | 2026-09-04 | N/A | 8.8 HIGH |
| A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It affects Puppet Enterprise versions 2018.1.8 through 2023.8.3 and 2025.3 and has been resolved in versions 2023.8.4 and 2025.4.0. | |||||
| CVE-2026-69414 | 1 Microsoft | 1 Malware Protection Engine | 2026-09-03 | N/A | 7.8 HIGH |
| Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". | |||||
| CVE-2026-78011 | 2026-09-03 | N/A | N/A | ||
| An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |||||
| CVE-2026-78010 | 2026-09-03 | N/A | N/A | ||
| A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process iallows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |||||
| CVE-2026-78009 | 2026-09-03 | N/A | N/A | ||
| An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |||||
