Total
397443 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-7953 | 2026-09-01 | N/A | N/A | ||
| A vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a threat actor could create, modify, and delete their own project. | |||||
| CVE-2026-12661 | 2026-09-01 | N/A | N/A | ||
| A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive. | |||||
| CVE-2026-81779 | 2026-09-01 | N/A | 10.0 CRITICAL | ||
| Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48. | |||||
| CVE-2026-81764 | 2026-09-01 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions. | |||||
| CVE-2026-82226 | 2026-09-01 | N/A | 9.8 CRITICAL | ||
| Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions. | |||||
| CVE-2026-82813 | 2026-09-01 | 6.4 MEDIUM | 5.4 MEDIUM | ||
| A vulnerability was detected in BEN Group TubeBuddy for YouTube Extension up to 5.8.4 on Chrome. This impacts the function TBGlobal.GetToken of the file tubebuddymaster1.js. The manipulation of the argument t/c/r results in insufficient verification of data authenticity. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure. | |||||
| CVE-2026-82552 | 2026-09-01 | 4.0 MEDIUM | 4.3 MEDIUM | ||
| A security vulnerability has been detected in Linux Foundation Magma 1.9.0. Affected by this vulnerability is an unknown functionality of the file tasks/ngap/ngap_amf.c of the component gNB Termination Handler. The manipulation leads to denial of service. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. | |||||
| CVE-2026-81280 | 2026-09-01 | N/A | 6.5 MEDIUM | ||
| Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions. | |||||
| CVE-2026-82970 | 2026-09-01 | N/A | 10.0 CRITICAL | ||
| Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1. | |||||
| CVE-2026-82802 | 2026-09-01 | 5.0 MEDIUM | 5.3 MEDIUM | ||
| A flaw has been found in NASA earthdata-search 1.0.0. Affected by this issue is the function OpenSearchGranuleSearchLambda of the file serverless/src/openSearchGranuleSearch/handler.js of the component granules Endpoint. Executing a manipulation of the argument openSearchOsdd can lead to server-side request forgery. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-82551 | 2026-09-01 | 5.0 MEDIUM | 5.3 MEDIUM | ||
| A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_handlers.c of the component NGSetup Handler. Executing a manipulation can lead to state issue. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. | |||||
| CVE-2026-82229 | 2026-09-01 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions. | |||||
| CVE-2026-82591 | 2026-09-01 | 4.3 MEDIUM | 5.3 MEDIUM | ||
| A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file code/AssetLib/MD5/MD5Loader.cpp. The manipulation of the argument iNewIndex leads to heap-based buffer overflow. The attack can only be performed from a local environment. The identifier of the patch is bf9dabb617c46e5133dac65cca6bff177917afcb. Applying a patch is the recommended action to fix this issue. | |||||
| CVE-2026-81298 | 2026-09-01 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions. | |||||
| CVE-2026-82957 | 2026-09-01 | 7.5 HIGH | 7.3 HIGH | ||
| A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook Subscription. Performing a manipulation of the argument url results in server-side request forgery. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-82919 | 2026-09-01 | 7.5 HIGH | 7.3 HIGH | ||
| A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the file views.py of the component edit Endpoint. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-81780 | 2026-09-01 | N/A | 10.0 CRITICAL | ||
| Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. | |||||
| CVE-2026-81297 | 2026-09-01 | N/A | 7.5 HIGH | ||
| Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions. | |||||
| CVE-2026-82815 | 2026-09-01 | 7.5 HIGH | 7.3 HIGH | ||
| A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file web/server.go of the component Middleware. This manipulation of the argument X-Forwarded-For/X-Real-IP/True-Client-IP causes improper access controls. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-82480 | 2026-09-01 | 6.5 MEDIUM | 7.4 HIGH | ||
| A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation of the argument TotalMsgSize/HdrSize results in integer underflow. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
