Unknown

    CVE-2026-87009

    https://github.com/squeeze440/inference-gateway-PoC

    Unknown

    CVE-2026-87008

    https://github.com/squeeze440/code-graph-rag-PoC

    Unknown

    CVE-2026-87007

    https://github.com/squeeze440/crw-PoC

    Unknown

    CVE-2026-87006

    https://github.com/squeeze440/terrapod-PoC

    Unknown

    CVE-2026-87005

    https://github.com/squeeze440/linux-entra-sso-PoC

    Unknown

    CVE-2026-87004

    https://github.com/squeeze440/tugtainer-PoC

    Unknown

    CVE-2026-87003

    https://github.com/squeeze440/gortex-PoC

    Unknown

    CVE-2026-87002

    https://github.com/squeeze440/obsidian-note-toolbar-PoC

    Unknown

    CVE-2026-87001

    https://github.com/squeeze440/openlore-PoC

    Unknown

    CVE-2026-87000

    https://github.com/squeeze440/zotlit-PoC

    Unknown

    CVE-2026-86999

    https://github.com/squeeze440/supernote-obsidian-plugin-PoC

    Unknown

    CVE-2026-86998

    https://github.com/squeeze440/pasteguard-PoC

    10
    Critical

    CVE-2026-86218

    Last Modified: 8 Sept 2026

    N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

    Published:6 Sept 2026
    9.2
    Critical

    CVE-2026-86060

    Last Modified: 10 Sept 2026

    RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

    Published:5 Sept 2026
    6.5
    Medium

    CVE-2026-85769

    Last Modified: 7 Sept 2026

    A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migration restore), a malformed state blob can supply an oversized skip-block length that is not validated against the remaining size of the input buffer. This can drive an internal size counter negative, which bypasses a subsequent bounds check due to an unsafe signed-to-unsigned conversion, causing the parser to read memory outside the bounds of the heap buffer holding the state data. Successful exploitation can crash the process hosting libtpms (such as swtpm), resulting in a denial of service of the emulated TPM device and the virtual machine that depends on it. No data corruption or information disclosure was confirmed.

    Published:4 Sept 2026
    7.9
    High

    CVE-2026-85649

    Last Modified: 4 Sept 2026

    (Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debian-minbase-install.sh. The installer invokes mkpasswd to generate yescrypt password hashes but does not check the command's return value and unconditionally accepts the result. If mkpasswd fails to generate a yescrypt hash, for example because an incompatible mkpasswd implementation or an environment without yescrypt support is used, the resulting password hash variable can be empty and the build proceeds. The resulting image can therefore contain empty password fields for the root and alpha accounts, potentially permitting passwordless authentication depending on the authentication configuration.

    Published:4 Sept 2026
    9.2
    Critical

    CVE-2026-85625

    Last Modified: 7 Sept 2026

    sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain, and dispatches any matched operator key including $where. The $where operation compiles a string value into a function using new Function unless CSP_ENABLED is set (not set by default). As a result, if a prototype-pollution primitive elsewhere in the process sets Object.prototype.$where to a malicious string, even benign filter calls such as sift({}) execute arbitrary JavaScript. Additionally, passing an untrusted query object containing a string $where directly to sift results in code execution under the default configuration.

    Published:4 Sept 2026
    8.8
    High

    CVE-2026-85046

    Last Modified: 8 Sept 2026

    Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published:3 Sept 2026
    8.8
    High

    CVE-2026-84645

    Last Modified: 3 Sept 2026

    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field values in user-submitted `config.xml` documents and subsequently handle HTTP requests via Stapler, resulting in remote code execution.

    Published:2 Sept 2026
    7.7
    High

    CVE-2026-84361

    Last Modified: 3 Sept 2026

    Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and source.url to an rsh: or jsh: P4PORT value. When the Perforce p4 client was installed and Composer installed the package from source through composer install or composer update, including --prefer-source, Composer\Util\Perforce passed the address to p4 without validation, causing p4 to run a local command with the privileges of the user or CI account. Packagist.org does not permit Perforce source metadata. This issue is fixed in versions 2.2.30 and 2.10.3.

    Published:1 Sept 2026
    5.4
    Medium

    CVE-2026-84118

    Last Modified: 2 Sept 2026

    Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

    Published:1 Sept 2026
    5.5
    Medium

    CVE-2026-83991

    Last Modified: 9 Sept 2026

    Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.

    Published:8 Sept 2026
    10
    Critical

    CVE-2026-83548

    Last Modified: 10 Sept 2026

    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

    Published:1 Sept 2026
    9.3
    Critical

    CVE-2026-82876

    Last Modified: 2 Sept 2026

    Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage. Attackers can generate arbitrary RSA key pairs, sign modified firmware with the private key, embed the matching modulus in the signature segment, and the controller accepts the tampered firmware as valid.

    Published:31 Aug 2026
    9.4
    Critical

    CVE-2026-82592

    Last Modified: 31 Aug 2026

    A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.

    Published:30 Aug 2026
    9.4
    Critical

    CVE-2026-82539

    Last Modified: 1 Sept 2026

    A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory corruption. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

    Published:30 Aug 2026
    9.8
    Critical

    CVE-2026-82329

    Last Modified: 3 Sept 2026

    JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

    Published:28 Aug 2026
    8.8
    High

    CVE-2026-82286

    Last Modified: 31 Aug 2026

    gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can supply absolute paths or parent-directory segments to overwrite existing files with content sourced from attacker-controlled URLs.

    Published:28 Aug 2026
    10
    Critical

    CVE-2026-82222

    Last Modified: 28 Aug 2026

    Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.

    Published:28 Aug 2026
    7.1
    High

    CVE-2026-82221

    Last Modified: 1 Sept 2026

    Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.

    Published:31 Aug 2026
    10
    Critical

    CVE-2026-81780

    Last Modified: 1 Sept 2026

    Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.

    Published:31 Aug 2026
    8.8
    High

    CVE-2026-81578

    Last Modified: 31 Aug 2026

    An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

    Published:28 Aug 2026
    8.8
    High

    CVE-2026-80724

    Last Modified: 7 Sept 2026

    In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: prevent read-only mappings from becoming writable vmclock_miscdev_mmap() rejects writable mappings of the shared vmclock ABI page with -EROFS, but leaves VM_MAYWRITE set. Userspace can map the page read-only and then upgrade it to writable with mprotect(), after which the guest can corrupt the host-written timekeeping data (sequence counter, UTC time, TSC offset) that the vmclock ABI defines as read-only. Clear VM_MAYWRITE on the read-only path so the mapping cannot be upgraded, as i915 does for its read-only objects and as fixed in drm/vc4 (CVE-2026-68445) and drm/panthor (CVE-2024-53071).

    Published:28 Aug 2026
    9.3
    Critical

    CVE-2026-80428

    Last Modified: 4 Sept 2026

    ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpoint and triggering deserialization via the Shibboleth back-channel logout endpoint. Attackers can write arbitrary serialized objects into session storage, then exploit an available POP gadget through the logout endpoint's unrestricted deserialization to write attacker-controlled PHP content to a web-accessible path and achieve remote code execution as the web server user.

    Published:26 Aug 2026
    7.1
    High

    CVE-2026-79617

    Last Modified: 10 Sept 2026

    Incorrect Permission Assignment for Critical Resource vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus LightDM Greeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pardus LightDM Greeter: before 0.4.15.

    Published:9 Sept 2026
    5.3
    Medium

    CVE-2026-79483

    Last Modified: 2 Sept 2026

    FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators via crafted JSON payloads to bypass authorization checks, resulting in unauthorized access to chat history titles of all users across the platform.

    Published:31 Aug 2026
    Low

    CVE-2026-79387

    Last Modified: 9 Sept 2026

    SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary user account fields (including passwords and roles) via crafted parameters to the User/mod interface, enabling account takeover.

    Published:9 Sept 2026
    Unknown

    CVE-2026-79303

    https://github.com/4ybrick/CVE-2026-79303

    8.8
    High

    CVE-2026-79266

    Last Modified: 31 Aug 2026

    Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)

    Published:25 Aug 2026
    8.8
    High

    CVE-2026-78938

    Last Modified: 27 Aug 2026

    Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published:25 Aug 2026
    7.5
    High

    CVE-2026-78906

    Last Modified: 26 Aug 2026

    Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published:25 Aug 2026
    8.8
    High

    CVE-2026-78905

    Last Modified: 26 Aug 2026

    Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published:25 Aug 2026
    9.6
    Critical

    CVE-2026-78904

    Last Modified: 27 Aug 2026

    Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Published:25 Aug 2026
    3.1
    Low

    CVE-2026-78903

    Last Modified: 28 Aug 2026

    Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

    Published:25 Aug 2026
    Unknown

    CVE-2026-78851

    https://github.com/SLO-CYBER-SEC/CVE-2026-78851

    Unknown

    CVE-2026-78850

    https://github.com/SLO-CYBER-SEC/CVE-2026-78850

    8.1
    High

    CVE-2026-78839

    Last Modified: 10 Sept 2026

    An arbitrary file upload vulnerability in AppNitro MachForm v30 allows attackers to execute arbitrary code via uploading a crafted .phar file.

    Published:4 Sept 2026
    6.5
    Medium

    CVE-2026-78838

    Last Modified: 10 Sept 2026

    A reflected cross-site scripting (XSS) vulnerability in the grid_datasource.php component of AppNitro MachForm v30 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted payload into the filter[filters][0][field] parameter.

    Published:8 Sept 2026
    7.5
    High

    CVE-2026-78837

    Last Modified: 10 Sept 2026

    A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 allows attackers to access sensitive database information via a crafted SQL statement.

    Published:8 Sept 2026
    Unknown

    CVE-2026-78804

    https://github.com/repo4Chu/CVE-2026-78804_Dolibarr_authenticated_SQL_injection

    Items Per Page