CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2026-84697

    Last Modified: 2 Sept 2026

    Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv4-translated IPv6 prefix, allowing server-side request forgery to internal destinations. Attackers can supply hostnames resolving to these addresses in message content to reach the link check API and proxy endpoint for accessing internal resources.

    Published: 2 Sept 2026
    9.3
    Critical

    CVE-2026-84696

    Last Modified: 3 Sept 2026

    Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.

    Published: 2 Sept 2026
    9.3
    Critical

    CVE-2026-84695

    Last Modified: 2 Sept 2026

    BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed through the image gallery API without content-type validation or CSP headers.

    Published: 2 Sept 2026
    8.7
    High

    CVE-2026-84694

    Last Modified: 2 Sept 2026

    Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell metacharacters into environment variable keys to execute arbitrary commands on the server host outside containers.

    Published: 2 Sept 2026
    2.1
    Low

    CVE-2026-84427

    Last Modified: 4 Sept 2026

    A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affected is an unknown function of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 2 Sept 2026
    2.1
    Low

    CVE-2026-84425

    Last Modified: 2 Sept 2026

    A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impacts the function BrowserTool of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulation results in denial of service. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 2 Sept 2026
    7.9
    High

    CVE-2026-78408

    Last Modified: 5 Sept 2026

    The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.

    Published: 2 Sept 2026
    7.1
    High

    CVE-2026-14199

    Last Modified: 3 Sept 2026

    Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).

    Published: 2 Sept 2026
    6.8
    Medium

    CVE-2026-12704

    Last Modified: 3 Sept 2026

    When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAML library skips validation of the InResponseTo field on all SAML responses, including SP-initiated logins. This removes anti-replay protection, allowing an attacker who obtains a valid signed SAML assertion to replay it and gain a session as the victim user. Only instances with the allow_idp_initiated SAML setting enabled are affected; this setting is off by default and Grafana OSS is not affected.

    Published: 2 Sept 2026
    7.8
    High

    CVE-2026-78410

    Last Modified: 4 Sept 2026

    A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.

    Published: 2 Sept 2026
    7.6
    High

    CVE-2025-46418

    Last Modified: 2 Sept 2026

    Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.

    Published: 2 Sept 2026
    8.6
    High

    CVE-2024-35585

    Last Modified: 2 Sept 2026

    Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.

    Published: 2 Sept 2026
    8.5
    High

    CVE-2026-76642

    Last Modified: 3 Sept 2026

    util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.

    Published: 2 Sept 2026
    7
    High

    CVE-2026-78409

    Last Modified: 3 Sept 2026

    The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.

    Published: 2 Sept 2026
    3.1
    Low

    CVE-2026-84331

    Last Modified: 3 Sept 2026

    Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 1 Sept 2026
    8.8
    High

    CVE-2026-84350

    Last Modified: 3 Sept 2026

    Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)

    Published: 1 Sept 2026
    4.3
    Medium

    CVE-2026-84356

    Last Modified: 3 Sept 2026

    UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)

    Published: 1 Sept 2026
    5.3
    Medium

    CVE-2026-84329

    Last Modified: 3 Sept 2026

    Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

    Published: 1 Sept 2026
    6.5
    Medium

    CVE-2026-84327

    Last Modified: 8 Sept 2026

    Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

    Published: 1 Sept 2026
    8.3
    High

    CVE-2026-84335

    Last Modified: 3 Sept 2026

    Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Sept 2026
    6.5
    Medium

    CVE-2026-84348

    Last Modified: 3 Sept 2026

    Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Sept 2026
    8.1
    High

    CVE-2026-84334

    Last Modified: 3 Sept 2026

    Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)

    Published: 1 Sept 2026
    5.4
    Medium

    CVE-2026-84330

    Last Modified: 8 Sept 2026

    UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Sept 2026
    6.5
    Medium

    CVE-2026-84332

    Last Modified: 3 Sept 2026

    Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Sept 2026
    3.1
    Low

    CVE-2026-84355

    Last Modified: 3 Sept 2026

    Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Sept 2026
    4.2
    Medium

    CVE-2026-84358

    Last Modified: 3 Sept 2026

    Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Sept 2026
    5.3
    Medium

    CVE-2026-84323

    Last Modified: 3 Sept 2026

    Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Sept 2026
    8.8
    High

    CVE-2026-84347

    Last Modified: 3 Sept 2026

    Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Sept 2026
    3.1
    Low

    CVE-2026-84328

    Last Modified: 3 Sept 2026

    Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-84325

    Last Modified: 3 Sept 2026

    Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)

    Published: 1 Sept 2026
    9.6
    Critical

    CVE-2026-84333

    Last Modified: 8 Sept 2026

    Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Sept 2026
    8.8
    High

    CVE-2026-84326

    Last Modified: 3 Sept 2026

    Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Sept 2026
    8.3
    High

    CVE-2026-84351

    Last Modified: 3 Sept 2026

    Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Sept 2026
    9
    Critical

    CVE-2026-84324

    Last Modified: 3 Sept 2026

    Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)

    Published: 1 Sept 2026
    3.1
    Low

    CVE-2026-84359

    Last Modified: 3 Sept 2026

    Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Sept 2026
    8.3
    High

    CVE-2026-84349

    Last Modified: 3 Sept 2026

    Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Sept 2026
    6.5
    Medium

    CVE-2026-84357

    Last Modified: 3 Sept 2026

    Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: High)

    Published: 1 Sept 2026
    9.6
    Critical

    CVE-2026-84354

    Last Modified: 3 Sept 2026

    Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Sept 2026
    9.6
    Critical

    CVE-2026-84352

    Last Modified: 8 Sept 2026

    Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

    Published: 1 Sept 2026
    9.6
    Critical

    CVE-2026-84353

    Last Modified: 8 Sept 2026

    Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

    Published: 1 Sept 2026
    7.5
    High

    CVE-2026-81928

    Last Modified: 3 Sept 2026

    Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG record. sig_data signs a message by re-encoding it, and removes TSIG records only from the additional section. A TSIG decoded into the answer or authority section survives that step and is signed again, so encoding re-enters sig_data with no termination condition. Decoding does not reject such a message: a TSIG that is not the last record on the wire raises "misplaced or corrupt TSIG", but the error is caught, reported as a warning, and the record is left in the packet. RFC 8945 section 5.2 requires the message to be dropped. The recursion is reached only when the decoded TSIG carries an empty MAC, since a MAC recovered from the wire short-circuits the signing step. It is reached only from code that re-encodes a message it decoded, such as a forwarder or a proxy. A decoded message that is never re-encoded is unaffected. Message direction does not matter: a query reaches the same path as a response. Each cycle re-encodes the whole message, so fewer than 100 bytes on the wire exhaust available memory and terminate the process.

    Published: 1 Sept 2026
    5.5
    Medium

    CVE-2026-84423

    Last Modified: 3 Sept 2026

    A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controllers/resource.go of the component upload-resource API. Such manipulation leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor deleted the GitHub issue for this vulnerability without any explanation. Afterwards the vendor was contacted early about this disclosure via email but did not respond in any way.

    Published: 1 Sept 2026
    6.9
    Medium

    CVE-2026-84483

    Last Modified: 4 Sept 2026

    WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens using the public site URL and current time. Attackers can forge authentication tokens by computing hash_hmac with the site's base URL as the key and submit arbitrary passwords to receive encrypted hashes, enabling offline precomputation attacks against stolen password databases.

    Published: 1 Sept 2026
    8.7
    High

    CVE-2026-84482

    Last Modified: 2 Sept 2026

    WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers can forge requests from sibling subdomains or unparseable long-gTLD origins to perform administrative ObjectYPT writes including live server configuration changes.

    Published: 1 Sept 2026
    6.9
    Medium

    CVE-2026-84481

    Last Modified: 2 Sept 2026

    WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors. Attackers can send an unauthenticated GET request to plugin/MobileManager/getConfiguration.json.php to obtain TLS private key file paths, socket configuration details, platform version, and debug flags enabling further targeted attacks.

    Published: 1 Sept 2026
    9.3
    Critical

    CVE-2026-84480

    Last Modified: 2 Sept 2026

    WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's password and gain full account access.

    Published: 1 Sept 2026
    9.3
    Critical

    CVE-2026-84479

    Last Modified: 2 Sept 2026

    WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a hardcoded literal ("AVideoEncoder"/"AVideoMobileApp") with no IP check or shared secret. An attacker who submits valid credentials and sets User-Agent: AVideoEncoder bypasses two-factor authentication, skips brute-force captcha escalation, and avoids being recorded in the login/device audit history. No patch is available at the time of publication.

    Published: 1 Sept 2026
    6.9
    Medium

    CVE-2026-84478

    Last Modified: 4 Sept 2026

    WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying directory traversal sequences in the code parameter. Attackers can exploit this to destroy audit logs and probe for file existence on the server, with the vulnerability enabling both file deletion and information disclosure about the filesystem.

    Published: 1 Sept 2026
    5.1
    Medium

    CVE-2026-84477

    Last Modified: 2 Sept 2026

    AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts. Unauthenticated attackers can access remindMe.php to execute stored XSS payloads in victim browsers without requiring authentication.

    Published: 1 Sept 2026
    8.7
    High

    CVE-2026-84476

    Last Modified: 2 Sept 2026

    WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can rotate the header value per request to bypass login rate limiting and perform unlimited credential guessing attacks.

    Published: 1 Sept 2026