Total
396958 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-84839 | 2026-09-03 | 5.0 MEDIUM | 5.3 MEDIUM | ||
| A vulnerability was determined in tsi-coop tsi-dpdp-cms up to 0.5.0. Affected by this issue is some unknown functionality of the file web.xml of the component Admin Console/DPO Compliance Console. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.5.1 can resolve this issue. It is suggested to upgrade the affected component. | |||||
| CVE-2026-84885 | 2026-09-03 | 4.0 MEDIUM | 4.3 MEDIUM | ||
| A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This impacts an unknown function of the file code_agent.py of the component CodeAgent. Such manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-84857 | 2026-09-03 | 5.0 MEDIUM | 5.3 MEDIUM | ||
| A flaw has been found in sigoden aichat up to 0.30.4. This affects an unknown function of the file src/serve.rs of the component API Endpoint. This manipulation causes uncontrolled memory allocation. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-51757 | 2026-09-03 | N/A | 9.8 CRITICAL | ||
| Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflow on the slave device via sending a crafted MQTT message to the cs_broker component. | |||||
| CVE-2026-51751 | 2026-09-03 | N/A | 9.8 CRITICAL | ||
| Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local mesh management data and reboot the system via sending a crafted MQTT message to the cs_broker component. | |||||
| CVE-2026-51760 | 2026-09-03 | N/A | 9.8 CRITICAL | ||
| Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity across mesh slaves via sending a crafted MQTT message to the cs_broker component. | |||||
| CVE-2026-51763 | 2026-09-03 | N/A | 9.8 CRITICAL | ||
| Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sending a crafted MQTT message to the cs_broker component. | |||||
| CVE-2026-51764 | 2026-09-03 | N/A | 9.8 CRITICAL | ||
| Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking files via sending a crafted MQTT message to the cs_broker component. | |||||
| CVE-2026-51744 | 2026-09-03 | N/A | 9.8 CRITICAL | ||
| Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronization from an attacker-controlled host via sending a crafted MQTT message to the cs_broker component. | |||||
| CVE-2026-51750 | 2026-09-03 | N/A | 9.8 CRITICAL | ||
| Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channel via sending a crafted MQTT message to the cs_broker component. | |||||
| CVE-2026-84357 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 6.5 MEDIUM |
| Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: High) | |||||
| CVE-2026-84358 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 4.2 MEDIUM |
| Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-84347 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 8.8 HIGH |
| Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-84348 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 6.5 MEDIUM |
| Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-51788 | 2026-09-03 | N/A | 7.5 HIGH | ||
| An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification function and the accounts/models.py component | |||||
| CVE-2025-9189 | 1 Ni | 1 Dasylab | 2026-09-03 | N/A | 7.8 HIGH |
| There is an out of bounds write vulnerability due to improper bounds checking resulting in a large destination address when parsing a DSB file with Digilent DASYLab. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted DSB file. The vulnerability affects all versions of DASYLab. | |||||
| CVE-2026-84349 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 8.3 HIGH |
| Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-84359 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 3.1 LOW |
| Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-81267 | 1 Mozilla | 1 Firefox Mobile | 2026-09-03 | N/A | 5.4 MEDIUM |
| A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0. | |||||
| CVE-2026-84669 | 2026-09-03 | N/A | 8.8 HIGH | ||
| A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permission on jobs that publish Allure report results to read arbitrary files on the Jenkins controller's file system. | |||||
