CVE Feed

    Dashboard / CVE

    7
    High

    CVE-2026-9634

    Last Modified: 1 Sept 2026

    A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges.

    Published: 1 Sept 2026
    7
    High

    CVE-2026-9633

    Last Modified: 1 Sept 2026

    A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges.

    Published: 1 Sept 2026
    2.1
    Low

    CVE-2026-84109

    Last Modified: 1 Sept 2026

    A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. Affected by this issue is the function getOrder of the file webmain/webmainAction.php. Executing a manipulation of the argument highorder can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Sept 2026
    4.8
    Medium

    CVE-2026-12661

    Last Modified: 3 Sept 2026

    A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition.  A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive.

    Published: 1 Sept 2026
    8.6
    High

    CVE-2025-12768

    Last Modified: 3 Sept 2026

    A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code execution on the affected device.

    Published: 1 Sept 2026
    7.8
    High

    CVE-2026-80047

    Last Modified: 3 Sept 2026

    A vulnerability in Hugging Face Transformers (versions >= 4.49.0 and <= 5.8.1) allows remote Python files to be written to local disk without user consent when using GenerativePreTrainedModel.load_custom_generate(). The function fetches and caches a remote module file before performing the required trust_remote_code consent check, inverting the security model enforced by other code-loading paths (such as AutoConfig, AutoModel, and AutoTokenizer). As a result, attacker‑controlled Python code from custom_generate/generate.py is copied into the user’s ~/.cache/huggingface/modules directory even if the user declines the trust prompt. Although execution is correctly gated, the file write is not reversible and can persist across sessions. This can lead to persistent, unauthorized files on disk and stale cache collisions where cached attacker code may later be executed during trusted model loads. The issue stems from an unconditional file write in dynamic_module_utils.py prior to any trust verification.

    Published: 1 Sept 2026
    8.8
    High

    CVE-2026-79684

    Last Modified: 4 Sept 2026

    Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-18210

    Last Modified: 2 Sept 2026

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection. This issue affects Products's Store: before 030631b2.

    Published: 1 Sept 2026
    8.7
    High

    CVE-2026-9625

    Last Modified: 1 Sept 2026

    A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover.

    Published: 1 Sept 2026
    8.7
    High

    CVE-2026-9624

    Last Modified: 1 Sept 2026

    A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length validation, requiring a  restart of the service to recover.

    Published: 1 Sept 2026
    8.7
    High

    CVE-2026-9622

    Last Modified: 1 Sept 2026

    A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover.

    Published: 1 Sept 2026
    9.2
    Critical

    CVE-2026-9621

    Last Modified: 1 Sept 2026

    A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover

    Published: 1 Sept 2026
    6.9
    Medium

    CVE-2026-13348

    Last Modified: 1 Sept 2026

    CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number of authentication attempts when redirect handling is disabled.

    Published: 1 Sept 2026
    7
    High

    CVE-2026-12663

    Last Modified: 3 Sept 2026

    A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.

    Published: 1 Sept 2026
    8.1
    High

    CVE-2026-19513

    Last Modified: 1 Sept 2026

    The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient validation of multi-file upload chunk state in the `GFAsyncUpload::upload()` function, where public form state URL hashes can be reused as chunk continuation hashes and attacker-controlled temporary filenames are accepted before sanitization. This makes it possible for unauthenticated attackers, when a public form contains a File Upload field with Multiple Files enabled, to upload a valid PNG/PDF polyglot to an attacker-selected public `.php` or `.html` filename in the Gravity Forms temporary upload directory. This can lead to remote code execution on WordPress systems that use NGINX or other non `.htaccess` respecting web servers. NOTE: During installation and activation, the Gravity Forms plugin places a `.htaccess` file in this directory, which prevents this vulnerability from being exploited despite the PHP file being written to the temporary upload directory. In these cases where PHP execution is blocked, attacker-written HTML can result in stored same-origin cross-site scripting if a victim visits the generated file URL.

    Published: 1 Sept 2026
    5.1
    Medium

    CVE-2026-13337

    Last Modified: 3 Sept 2026

    CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into the NetBotz via the web-service interface or webui.

    Published: 1 Sept 2026
    7
    High

    CVE-2026-84233

    Last Modified: 4 Sept 2026

    A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability.

    Published: 1 Sept 2026
    8.7
    High

    CVE-2026-9637

    Last Modified: 1 Sept 2026

    A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover

    Published: 1 Sept 2026
    7.3
    High

    CVE-2026-13336

    Last Modified: 3 Sept 2026

    CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause execution of Linux Operating system commands when a system back up is restored that has been maliciously modified.

    Published: 1 Sept 2026
    8.8
    High

    CVE-2026-58572

    Last Modified: 1 Sept 2026

    Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-18808

    Last Modified: 2 Sept 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO (Klemsan Internet Objects): before v1.9.

    Published: 1 Sept 2026
    8.2
    High

    CVE-2024-10085

    Last Modified: 3 Sept 2026

    CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communication platform when a large number of OPC UA requests are sent to the platform.

    Published: 1 Sept 2026
    8.5
    High

    CVE-2026-16675

    Last Modified: 1 Sept 2026

    A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack these console windows to obtain a SYSTEM-level command prompt, allowing full access to all files, processes, and system resources.

    Published: 1 Sept 2026
    8.7
    High

    CVE-2026-84235

    Last Modified: 3 Sept 2026

    A denial-of-service security issue exists in the affected product. The security issue stems from a crafted CIP packet being sent crashing the module. The device requires a restart to recover.

    Published: 1 Sept 2026
    8.8
    High

    CVE-2026-79683

    Last Modified: 1 Sept 2026

    Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write attacker-controlled content to arbitrary filesystem paths.

    Published: 1 Sept 2026
    8.7
    High

    CVE-2026-19472

    Last Modified: 1 Sept 2026

    A denial-of-service security issue exists within ArmorStart® LT. The security issue stems from improper handling of a crafted HTTP PUT request sent to the embedded web server. This can result in a loss of web server availability

    Published: 1 Sept 2026
    6.9
    Medium

    CVE-2026-19471

    Last Modified: 1 Sept 2026

    Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker to inject malicious scripts that will be executed when other users access the affected page.

    Published: 1 Sept 2026
    8.8
    High

    CVE-2026-58575

    Last Modified: 1 Sept 2026

    Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges to Administrator.

    Published: 1 Sept 2026
    9.2
    Critical

    CVE-2026-84149

    Last Modified: 2 Sept 2026

    This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could exploit this vulnerability by accessing the exposed .git directory and retrieving repository metadata and associated files, which could allow reconstruction of the application's source code.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-18765

    Last Modified: 2 Sept 2026

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This issue affects E-OSB: before V02.26.07.08.01.

    Published: 1 Sept 2026
    9.2
    Critical

    CVE-2026-84148

    Last Modified: 1 Sept 2026

    This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by manipulating parameter which could lead to exposure of sensitive information belonging to other users on the targeted system.

    Published: 1 Sept 2026
    10
    Critical

    CVE-2026-84147

    Last Modified: 1 Sept 2026

    This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by uploading arbitrary files to a web accessible directory on the targeted system Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code and compromise the targeted system.

    Published: 1 Sept 2026
    6.4
    Medium

    CVE-2026-7877

    Last Modified: 1 Sept 2026

    The WP Recipe Maker Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-call-to-action' shortcode in all versions up to, and including, 10.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 1 Sept 2026
    7.5
    High

    CVE-2026-84144

    Last Modified: 3 Sept 2026

    Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-84143

    Last Modified: 3 Sept 2026

    Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-84142

    Last Modified: 3 Sept 2026

    Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-84141

    Last Modified: 3 Sept 2026

    Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-84140

    Last Modified: 3 Sept 2026

    Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

    Published: 1 Sept 2026
    6.1
    Medium

    CVE-2026-84139

    Last Modified: 3 Sept 2026

    Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

    Published: 1 Sept 2026
    6.5
    Medium

    CVE-2026-84138

    Last Modified: 3 Sept 2026

    Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

    Published: 1 Sept 2026
    4.3
    Medium

    CVE-2026-84137

    Last Modified: 3 Sept 2026

    Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

    Published: 1 Sept 2026
    6.1
    Medium

    CVE-2026-84136

    Last Modified: 3 Sept 2026

    Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-84135

    Last Modified: 3 Sept 2026

    Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-84134

    Last Modified: 3 Sept 2026

    Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-84133

    Last Modified: 3 Sept 2026

    Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

    Published: 1 Sept 2026
    7.5
    High

    CVE-2026-84132

    Last Modified: 3 Sept 2026

    Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

    Published: 1 Sept 2026
    7.5
    High

    CVE-2026-84130

    Last Modified: 3 Sept 2026

    Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-84129

    Last Modified: 3 Sept 2026

    Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

    Published: 1 Sept 2026
    8.8
    High

    CVE-2026-84128

    Last Modified: 3 Sept 2026

    Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

    Published: 1 Sept 2026
    4.3
    Medium

    CVE-2026-84127

    Last Modified: 3 Sept 2026

    Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 155.

    Published: 1 Sept 2026