| CVE-2026-84364 | MEDIUM | 5.3 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, when pa… | 2026-09-01 |
| CVE-2026-84365 | MEDIUM | 6.5 | Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.… | 2026-09-01 |
| CVE-2026-84366 | HIGH | 7.4 | Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloa… | 2026-09-01 |
| CVE-2026-84367 | LOW | 3.7 | joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.5 and 18.2.4, … | 2026-09-01 |
| CVE-2026-84368 | LOW | 3.7 | joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.6 and 18.2.5, … | 2026-09-01 |
| CVE-2026-84369 | MEDIUM | 6.1 | SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. Fro… | 2026-09-01 |
| CVE-2026-84370 | HIGH | 8.2 | SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. Fro… | 2026-09-01 |
| CVE-2026-84371 | MEDIUM | 5.4 | ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sa… | 2026-09-01 |
| CVE-2026-84470 | MEDIUM | 6.4 | A flaw was found in Ansible Automation Platform's automation-controller (AWX).
The Bulk Job Launch API (POST /… | 2026-09-01 |
| CVE-2023-54391 | CRITICAL | 9.8 | Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-acc… | 2026-09-01 |
| CVE-2026-18730 | NA | N/A | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an … | 2026-09-01 |
| CVE-2026-19118 | NA | N/A | A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allow… | 2026-09-01 |
| CVE-2026-75604 | CRITICAL | 9.0 | Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, N… | 2026-09-01 |
| CVE-2026-76851 | NA | N/A | A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed rem… | 2026-09-01 |
| CVE-2026-83548 | CRITICAL | 10.0 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an uninten… | 2026-09-01 |
| CVE-2026-83549 | HIGH | 7.8 | Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')… | 2026-09-01 |
| CVE-2026-84288 | MEDIUM | 4.3 | A vulnerability has been found in NousResearch hermes-agent up to 0.18.2. This affects the function HermesACPA… | 2026-09-01 |
| CVE-2026-84289 | MEDIUM | 4.3 | A vulnerability was found in NousResearch hermes-agent up to 0.18.2. This vulnerability affects the function l… | 2026-09-01 |
| CVE-2026-84372 | CRITICAL | 9.8 | Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until versio… | 2026-09-01 |
| CVE-2026-84373 | MEDIUM | 5.9 | Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 and 5.0.0-rc.2, the public mockerPlugin… | 2026-09-01 |
| CVE-2026-84374 | HIGH | 7.5 | Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/File… | 2026-09-01 |
| CVE-2026-84375 | HIGH | 7.5 | js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js… | 2026-09-01 |
| CVE-2026-84637 | NA | N/A | Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on… | 2026-09-01 |
| CVE-2026-84639 | NA | N/A | Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnera… | 2026-09-01 |
| CVE-2026-84640 | NA | N/A | A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerabili… | 2026-09-01 |
| CVE-2026-84641 | NA | N/A | A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response… | 2026-09-01 |
| CVE-2026-84642 | NA | N/A | The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression … | 2026-09-01 |
| CVE-2026-84208 | HIGH | 7.5 | AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugi… | 2026-09-01 |
| CVE-2026-84423 | HIGH | 7.3 | A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controller… | 2026-09-01 |
| CVE-2026-84476 | HIGH | 7.5 | WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing… | 2026-09-01 |
| CVE-2026-84477 | MEDIUM | 5.4 | AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users wi… | 2026-09-01 |
| CVE-2026-84478 | HIGH | 7.3 | WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthe… | 2026-09-01 |
| CVE-2026-84479 | CRITICAL | 9.1 | WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the clie… | 2026-09-01 |
| CVE-2026-84480 | CRITICAL | 9.8 | WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing att… | 2026-09-01 |
| CVE-2026-84481 | NA | N/A | WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfi… | 2026-09-01 |
| CVE-2026-84482 | HIGH | 8.8 | WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() an… | 2026-09-01 |
| CVE-2026-84483 | MEDIUM | 5.3 | WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that … | 2026-09-01 |
| CVE-2026-82593 | CRITICAL | 9.9 | A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formL… | 2026-08-31 |
| CVE-2026-82594 | MEDIUM | 5.0 | A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function… | 2026-08-31 |
| CVE-2026-82595 | HIGH | 7.4 | A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 … | 2026-08-31 |
| CVE-2026-82596 | LOW | 3.3 | A vulnerability was determined in LatencyUtils up to 2.0.3. Affected by this issue is the function LatencyStat… | 2026-08-31 |
| CVE-2026-77956 | NA | N/A | Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, u… | 2026-08-31 |
| CVE-2026-81315 | NA | N/A | Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP serv… | 2026-08-31 |
| CVE-2026-82597 | HIGH | 7.4 | A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function setUssd of… | 2026-08-31 |
| CVE-2026-82598 | HIGH | 7.3 | A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php o… | 2026-08-31 |
| CVE-2026-82599 | MEDIUM | 5.4 | A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of … | 2026-08-31 |
| CVE-2026-75760 | NA | N/A | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses pro… | 2026-08-31 |
| CVE-2026-82564 | NA | N/A | Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an ide… | 2026-08-31 |
| CVE-2026-82579 | NA | N/A | Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker wh… | 2026-08-31 |
| CVE-2026-82580 | NA | N/A | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses int… | 2026-08-31 |