| CVE-2026-84165 | NA | N/A | A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versio… | 2026-09-01 |
| CVE-2023-54356 | LOW | 3.7 | Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA an… | 2026-09-01 |
| CVE-2025-15613 | MEDIUM | 6.5 | Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality.… | 2026-09-01 |
| CVE-2026-10420 | MEDIUM | 5.5 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation.
This i… | 2026-09-01 |
| CVE-2026-11873 | MEDIUM | 6.5 | An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with in… | 2026-09-01 |
| CVE-2026-18550 | CRITICAL | 9.8 | The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover… | 2026-09-01 |
| CVE-2026-76111 | HIGH | 8.8 | Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileg… | 2026-09-01 |
| CVE-2026-77194 | MEDIUM | 5.3 | The Simple Membership plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Acc… | 2026-09-01 |
| CVE-2026-83595 | HIGH | 8.1 | AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to… | 2026-09-01 |
| CVE-2026-84187 | HIGH | 8.2 | AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticat… | 2026-09-01 |
| CVE-2026-84188 | MEDIUM | 4.8 | LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.… | 2026-09-01 |
| CVE-2026-84189 | HIGH | 8.1 | LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-co… | 2026-09-01 |
| CVE-2026-84190 | HIGH | 7.2 | LibreNMS versions before 26.5.0 contain a remote code execution vulnerability in the AboutController where the… | 2026-09-01 |
| CVE-2026-84191 | MEDIUM | 6.1 | LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages where mplsVpn… | 2026-09-01 |
| CVE-2026-84192 | HIGH | 7.1 | LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that outpu… | 2026-09-01 |
| CVE-2026-84193 | NA | N/A | LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that… | 2026-09-01 |
| CVE-2026-84194 | NA | N/A | LibreNMS versions >= 23.10.0 and < 26.2.0 (fixed in 26.4.0) contain an authenticated OS command injection vuln… | 2026-09-01 |
| CVE-2026-84195 | HIGH | 7.7 | Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP … | 2026-09-01 |
| CVE-2026-84196 | HIGH | 7.7 | Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows … | 2026-09-01 |
| CVE-2026-84199 | HIGH | 7.7 | Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The … | 2026-09-01 |
| CVE-2026-84200 | CRITICAL | 9.0 | Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mod… | 2026-09-01 |
| CVE-2026-18765 | CRITICAL | 9.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity… | 2026-09-01 |
| CVE-2026-19471 | NA | N/A | Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs when user … | 2026-09-01 |
| CVE-2026-19472 | NA | N/A | A denial-of-service security issue exists within ArmorStart® LT. The security issue stems from improper handli… | 2026-09-01 |
| CVE-2026-51741 | NA | N/A | Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthe… | 2026-09-01 |
| CVE-2026-51742 | MEDIUM | 5.9 | Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat… | 2026-09-01 |
| CVE-2026-51743 | CRITICAL | 9.1 | Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthent… | 2026-09-01 |
| CVE-2026-51744 | NA | N/A | Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unaut… | 2026-09-01 |
| CVE-2026-51745 | MEDIUM | 5.3 | Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthen… | 2026-09-01 |
| CVE-2026-51747 | NA | N/A | Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated… | 2026-09-01 |
| CVE-2026-53682 | MEDIUM | 5.3 | An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts … | 2026-09-01 |
| CVE-2026-58575 | HIGH | 8.8 | Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could p… | 2026-09-01 |
| CVE-2026-79683 | HIGH | 8.8 | Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited priv… | 2026-09-01 |
| CVE-2026-7877 | MEDIUM | 6.4 | The WP Recipe Maker Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… | 2026-09-01 |
| CVE-2026-84061 | MEDIUM | 6.3 | A security flaw has been discovered in zhongyu09 OpenChatBI up to 0.3.0. Affected by this vulnerability is the… | 2026-09-01 |
| CVE-2026-84117 | HIGH | 8.8 | Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.… | 2026-09-01 |
| CVE-2026-84118 | MEDIUM | 5.4 | Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2… | 2026-09-01 |
| CVE-2026-84119 | CRITICAL | 9.6 | Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox… | 2026-09-01 |
| CVE-2026-84120 | MEDIUM | 5.4 | Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, … | 2026-09-01 |
| CVE-2026-84121 | CRITICAL | 9.6 | Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 1… | 2026-09-01 |
| CVE-2026-84122 | MEDIUM | 5.4 | Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, … | 2026-09-01 |
| CVE-2026-84123 | HIGH | 8.8 | Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in … | 2026-09-01 |
| CVE-2026-84124 | MEDIUM | 5.4 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140… | 2026-09-01 |
| CVE-2026-84125 | MEDIUM | 5.4 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153… | 2026-09-01 |
| CVE-2026-84126 | MEDIUM | 4.3 | Incorrect boundary conditions in the Layout: Grid component. This vulnerability was fixed in Firefox 155 and T… | 2026-09-01 |
| CVE-2026-84127 | MEDIUM | 4.3 | Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in … | 2026-09-01 |
| CVE-2026-84128 | HIGH | 8.8 | Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderb… | 2026-09-01 |
| CVE-2026-84129 | NA | N/A | Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ES… | 2026-09-01 |
| CVE-2026-84130 | NA | N/A | Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox… | 2026-09-01 |
| CVE-2026-84131 | HIGH | 8.8 | Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox… | 2026-09-01 |