Total
396952 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-19505 | 2026-09-03 | N/A | 9.8 CRITICAL | ||
| Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to bypass authentication and obtain administrative access via a forged JWT containing an invalid RSA signature. | |||||
| CVE-2026-19509 | 2026-09-03 | N/A | 6.5 MEDIUM | ||
| Improper input validation in `ajaxSet_wireless_network_configuration.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows an authenticated attacker to cause denial of service via a crafted `ssid_number` parameter. | |||||
| CVE-2026-0299 | 1 Paloaltonetworks | 1 Globalprotect | 2026-09-03 | N/A | 7.8 HIGH |
| Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges. The GlobalProtect app on iOS, Android, and Chrome OS is not affected. | |||||
| CVE-2026-9203 | 1 Progress | 1 Marklogic Server | 2026-09-03 | N/A | 8.5 HIGH |
| A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance. | |||||
| CVE-2026-9195 | 1 Progress | 1 Marklogic Server | 2026-09-03 | N/A | 9.3 CRITICAL |
| A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture credentials, and perform privileged actions on the administrator's behalf. | |||||
| CVE-2026-19912 | 2026-09-03 | N/A | 9.8 CRITICAL | ||
| The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. mwEmbedLoader.php accepts a user‑controlled ServiceUrl, whose response is passed to unserialize(), and the resulting object’s fields are written to a cache path derived from attacker‑supplied uiconf_id without proper path validation. An attacker can write arbitrary files into web‑accessible locations and achieve code execution as the webserver user. Affected versions include html5lib v2.45, v2.103 and earlier, and other v2.x releases exposing the vulnerable endpoint. | |||||
| CVE-2026-19913 | 2026-09-03 | N/A | 7.5 HIGH | ||
| The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter is used as the base URL for a backend request and accepts non‑HTTP schemes such as file://. When an exception or error occurs, the response is subsequently deserialized and its raw contents are reflected to the client in an error message; this enables an unauthenticated, remote attacker to read any arbitrary internal file reachable by the server. Affected versions include html5lib v2.45, v2.103 and earlier, and other v2.x releases exposing the vulnerable endpoint. | |||||
| CVE-2026-9193 | 1 Progress | 1 Marklogic Server | 2026-09-03 | N/A | 9.9 CRITICAL |
| An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database. | |||||
| CVE-2026-84350 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 8.8 HIGH |
| Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low) | |||||
| CVE-2026-84351 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-09-03 | N/A | 8.3 HIGH |
| Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-15724 | 1 Progress | 1 Sharefile Storage Zones Controller | 2026-09-03 | N/A | 8.7 HIGH |
| In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server. | |||||
| CVE-2026-84354 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 9.6 CRITICAL |
| Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-2514 | 1 Progress | 1 Flowmon Anomaly Detection System | 2026-09-03 | N/A | 6.1 MEDIUM |
| In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed by Flowmon ADS and viewed by an authenticated user, could result in unintended actions being executed in the user's browser context. | |||||
| CVE-2026-2513 | 1 Progress | 1 Flowmon Anomaly Detection System | 2026-09-03 | N/A | 6.1 MEDIUM |
| A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session. | |||||
| CVE-2026-84355 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 3.1 LOW |
| Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-27875 | 2026-09-03 | N/A | N/A | ||
| Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data. This issue affects Simplex Incident Manager / Autocall Fire Administrator: before 2.01.05. | |||||
| CVE-2026-27871 | 2026-09-03 | N/A | N/A | ||
| Cwe-327 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Johnson Controls TL280 allows Cryptanalytic Attack. This issue affects TL280: before 5.63. | |||||
| CVE-2026-64887 | 2026-09-03 | N/A | N/A | ||
| Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack. This issue affects Airwall: before 4.1. | |||||
| CVE-2026-34491 | 2026-09-03 | N/A | N/A | ||
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls Metasys 14 and Johnson Controls Metasys 15 allows Cross Site Scripting. This issue affects Metasys 14: before 14.1.5; Metasys 15: before 15.0.1. | |||||
| CVE-2026-64896 | 2026-09-03 | N/A | N/A | ||
| Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects T2000: before 31.6. | |||||
