Total
397448 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-51610 | 2026-09-01 | N/A | 4.3 MEDIUM | ||
| Incorrect access control in the RebootSystem function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force an immediate reboot via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51376 | 2026-09-01 | N/A | 6.5 MEDIUM | ||
| An issue in BitChat for iOS v1.15.0 allows a remote attacker to cause a denial of service via an unauthenticated MESSAGE packet into the mesh gossip cache | |||||
| CVE-2026-26459 | 2026-09-01 | N/A | 7.5 HIGH | ||
| ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a vulnerability in the option parsing logic that causes a segmentation fault when processing malformed COAP messages with insufficient option data. | |||||
| CVE-2026-26457 | 2026-09-01 | N/A | 7.5 HIGH | ||
| ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_dump_msg() function when processing COAP messages containing options with zero length. | |||||
| CVE-2026-26453 | 2026-09-01 | N/A | 7.5 HIGH | ||
| ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_server_handle_session() function when processing COAP messages containing URI_PATH options with NULL data pointers. When the server searches for a URI_PATH option matching the string "separate", it directly calls strncmp() on option_list[i].data without checking if the pointer is NULL. This causes a segmentation fault when the option's data field is NULL. | |||||
| CVE-2026-26452 | 2026-09-01 | N/A | 7.5 HIGH | ||
| ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 lcontains a vulnerability in the option parsing logic that causes a segmentation fault when processing COAP messages containing invalid option numbers. | |||||
| CVE-2026-47628 | 2 Linux, Nvidia | 2 Linux Kernel, Triton Inference Server | 2026-09-01 | N/A | 7.5 HIGH |
| NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service. | |||||
| CVE-2026-77073 | 1 N8n | 1 N8n | 2026-09-01 | N/A | 4.3 MEDIUM |
| n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authentication type is set to an expression. Attackers with a valid MCP Bearer API key and knowledge of a target credential ID can persist unauthorized cross-project credential references on workflows in different projects. | |||||
| CVE-2026-77068 | 1 N8n | 1 N8n | 2026-09-01 | N/A | 8.8 HIGH |
| n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk node-schema loader used for MCP node-schema loading. The loader derives a node's schema module path directly from the attacker-supplied node type string without validating path-traversal sequences. An authenticated user with global:member privileges can reference malicious files via path traversal, causing code execution in the n8n main process. | |||||
| CVE-2026-77085 | 1 N8n | 1 N8n | 2026-09-01 | N/A | 6.5 MEDIUM |
| n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent tool. The tool sent requests to the user-supplied API URL using a raw HTTP client that did not route through n8n's centralized SSRF protection. On instances with N8N_SSRF_PROTECTION_ENABLED=true, an authenticated user with permission to create SearXNG credentials and configure a personal agent could set the API URL to an internal host, causing the n8n server to connect to that host and return the response content through the Agent chat output. | |||||
| CVE-2026-76197 | 3 Adobe, Linux, Microsoft | 3 Campaign, Linux Kernel, Windows | 2026-09-01 | N/A | 10.0 CRITICAL |
| Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. | |||||
| CVE-2026-65081 | 2 Linux, Nvidia | 2 Linux Kernel, Nemoclaw | 2026-09-01 | N/A | 8.1 HIGH |
| NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service. | |||||
| CVE-2026-65092 | 2 Linux, Nvidia | 2 Linux Kernel, Openshell | 2026-09-01 | N/A | 8.5 HIGH |
| NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering. | |||||
| CVE-2026-65093 | 2 Linux, Nvidia | 2 Linux Kernel, Openshell | 2026-09-01 | N/A | 9.9 CRITICAL |
| NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | |||||
| CVE-2026-65098 | 2 Linux, Nvidia | 2 Linux Kernel, Nemoclaw | 2026-09-01 | N/A | 8.1 HIGH |
| NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. | |||||
| CVE-2026-65099 | 2 Linux, Nvidia | 2 Linux Kernel, Nemoclaw | 2026-09-01 | N/A | 7.8 HIGH |
| NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service. | |||||
| CVE-2026-65105 | 2 Linux, Nvidia | 2 Linux Kernel, Nemoclaw | 2026-09-01 | N/A | 8.1 HIGH |
| NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service. | |||||
| CVE-2026-59271 | 1 Vmware | 1 Spring Advanced Message Queuing Protocol | 2026-09-01 | N/A | 5.3 MEDIUM |
| When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier | |||||
| CVE-2026-59274 | 1 Vmware | 1 Spring Integration | 2026-09-01 | N/A | 6.5 MEDIUM |
| The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an attacker can send a zip archive that can exhaust JVM heap memory, causing a denial-of-service outage. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 | |||||
| CVE-2026-59275 | 1 Vmware | 1 Spring Advanced Message Queuing Protocol | 2026-09-01 | N/A | 6.6 MEDIUM |
| A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located in that process. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier | |||||
