Total
397360 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-65937 | 1 Progress | 1 Whatsup Gold | 2026-09-02 | N/A | 8.0 HIGH |
| In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content. | |||||
| CVE-2026-65938 | 1 Progress | 1 Whatsup Gold | 2026-09-02 | N/A | 4.3 MEDIUM |
| In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions. | |||||
| CVE-2026-65939 | 1 Progress | 1 Whatsup Gold | 2026-09-02 | N/A | 6.8 MEDIUM |
| In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root. | |||||
| CVE-2026-65940 | 1 Progress | 1 Whatsup Gold | 2026-09-02 | N/A | 6.8 MEDIUM |
| In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server. | |||||
| CVE-2026-65941 | 1 Progress | 1 Whatsup Gold | 2026-09-02 | N/A | 8.8 HIGH |
| In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account. | |||||
| CVE-2026-83744 | 2026-09-02 | 4.0 MEDIUM | 4.3 MEDIUM | ||
| A security vulnerability has been detected in invoiceninja Invoice Ninja up to 5.13.26. This vulnerability affects the function Purify::isHostSafe of the file app/Services/Pdf/Purify.php of the component invoices Endpoint. The manipulation of the argument notes leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-82954 | 2026-09-02 | 9.0 HIGH | 9.9 CRITICAL | ||
| A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of the argument path results in path traversal. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-82637 | 2026-09-02 | N/A | 5.3 MEDIUM | ||
| browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute paths to save_recording_path, save_trace_path, save_agent_history_path, or save_download_path parameters. Attackers can exploit this via the unauthenticated Gradio interface to create directories anywhere the root-running container has write access. | |||||
| CVE-2026-82224 | 2026-09-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions. | |||||
| CVE-2026-81765 | 2026-09-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions. | |||||
| CVE-2026-81160 | 2026-09-02 | N/A | 6.1 MEDIUM | ||
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. This issue affects Slick Carousel versions: from 0.0.0 to 2.1.0. | |||||
| CVE-2026-80101 | 2 Gimp, Redhat | 2 Gimp, Enterprise Linux | 2026-09-02 | N/A | 4.4 MEDIUM |
| A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image file, the plugin validates the image width and bytes-per-line parameters independently rather than ensuring their combined values are consistent with the allocated buffer size. This incorrect validation leads to improper bounds checking, causing a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents into the produced image. | |||||
| CVE-2026-77189 | 2026-09-02 | N/A | 6.5 MEDIUM | ||
| The Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) plugin for WordPress is vulnerable to generic SQL Injection via 'order' Shortcode Attribute in all versions up to, and including, 1.8.12.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The [charitable_donors] shortcode is accessible to Contributor-level users via draft or pending post previews, providing an authenticated but low-privileged entry point for exploitation. | |||||
| CVE-2026-76006 | 2026-09-02 | N/A | 4.9 MEDIUM | ||
| The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 6.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerability exists across two execution paths — $wpdb->get_var() in record_count() and $wpdb->get_results() in prepare_items()/get_image_categories() — enabling both blind and UNION-based exfiltration techniques. | |||||
| CVE-2026-70336 | 1 Microsoft | 1 Visual Studio Code | 2026-09-02 | N/A | 8.8 HIGH |
| Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-70335 | 1 Microsoft | 1 Visual Studio Code | 2026-09-02 | N/A | 7.8 HIGH |
| Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally. | |||||
| CVE-2026-69320 | 1 Microsoft | 1 Visual Studio Code | 2026-09-02 | N/A | 8.8 HIGH |
| Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69306 | 1 Microsoft | 1 Visual Studio Code | 2026-09-02 | N/A | 8.2 HIGH |
| Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | |||||
| CVE-2026-69278 | 1 Microsoft | 1 Visual Studio Code | 2026-09-02 | N/A | 7.8 HIGH |
| Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |||||
| CVE-2026-65789 | 1 Microsoft | 6 Windows 10 1607, Windows 10 1809, Windows Server 2016 and 3 more | 2026-09-02 | N/A | 8.1 HIGH |
| Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | |||||
