CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Sep 9, 2026
Jul 31, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build 118101 allows attackers to execute arbitrary Javascript in the context of the victim's browser via...Show more
A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build 118101 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.Show less
-
-
Sep 9, 2026
Sep 2, 2026
7.3 HIGH· v4
7.5 HIGH· v3
N/A· v2
The mobile Smart Connect dashboard UI was subject to manipulation by 3rd party apps. When paired with a phishing attack, this manipulation could result in escalated privileges of an attacker within the system.
-
-
Sep 9, 2026
Sep 2, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if...Show more
In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Continued exploitation causes a denial of service. No remote code execution is possible. Both IKEv1 and IKEv2 are affected. The vulnerability is only exploitable when both the OS and libreswan are running in FIPS mode and at least one CA certificate is loaded. The CERT payload is processed before peer authentication, so no credentials are needed to exploit this. Configurations using only PreSharedKey (PSK) authentication with no CA certificates loaded in the NSS database are not vulnerable.Show less
-
-
Sep 9, 2026
Aug 4, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100R002 and H3C MC102G HM1A0V200R010 contain multip...Show more
H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100R002 and H3C MC102G HM1A0V200R010 contain multiple command injection vulnerabilities in the /api/esps request handler. The affected object interfaces and methods are esps.dhcpd.vlan (getlist, delete), esps.filter.url (add, modify), esps.apcm.version (delete, H3C Magic NX15 only), esps.swcm.version (delete, upgrade, all affected models except H3C Magic NX15), and esps.system.ntp (set, all affected models except H3C Magic NX15). Attacker-controlled request parameters are incorporated into shell expressions executed by eval without adequate validation, allowing a remote attacker to execute arbitrary commands as root and gain complete control of the affected device.Show less
-
-
Sep 9, 2026
Sep 6, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_...Show more
Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). The shared-object loader treats an http-prefixed path as a download URL, writes the body to a temporary .so, and passes it to Go's plugin.Open. After a successful open, optional Init runs immediately with the supplied config as the Bifrost process user. On documented dynamically linked builds (DYNAMIC=1 / no static-link flags), which the vendor requires for custom Go plugins, plugin.Open is expected to succeed and this is unauthenticated remote code execution. On the published statically linked Docker image, plugin.Open fails with Dynamic loading not supported, so that build class is only server-side request forgery. Attack complexity is High because the attacker cannot force RCE on the default static image and a loadable plugin must match the host Go version, OS, architecture, and linkage. The 1.6.x HTTP transport line through 1.6.11 does not contain the fix.Show less
1Ibm
1I
Sep 9, 2026
Sep 4, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
-
-
Sep 9, 2026
Sep 2, 2026
8.7 HIGH· v4
N/A· v3
N/A· v2
The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if th...Show more
The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permission (which is required to change others’ passwords).Show less
-
-
Sep 9, 2026
Sep 4, 2026
9.2 CRITICAL· v4
N/A· v3
N/A· v2
An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a map...Show more
An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulnerability in version 16.31.Show less
-
-
Sep 9, 2026
Sep 4, 2026
8.2 HIGH· v4
N/A· v3
N/A· v2
Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthentic...Show more
Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.Show less
-
-
Sep 9, 2026
Sep 1, 2026
N/A· v4
5.9 MEDIUM· v3
N/A· v2
A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation of file path parameters. By leveraging directory traversal sequences and their encoded variants,...Show more
A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation of file path parameters. By leveraging directory traversal sequences and their encoded variants, an attacker may bypass directory restrictions and access files outside the application's intended file system scope. Successful exploitation would require knowledge of valid file names and paths. Depending on the privileges of the affected component, exploitation could result in the disclosure of sensitive information, including configuration files, environment settings, application assets, and log data. The vulnerability has been remediated through enhanced path validation and secure path resolution controls that prevent access to unauthorised locations.Show less
-
-
Sep 9, 2026
Aug 26, 2026
9.3 CRITICAL· v4
N/A· v3
N/A· v2
A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.
-
-
Sep 9, 2026
Aug 4, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker can read arbitrary fil...Show more
An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker can read arbitrary files outside the base directory.Show less
-
-
Sep 9, 2026
Aug 4, 2026
N/A· v4
7.3 HIGH· v3
N/A· v2
A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to execute arbitrary code. By placing a crafted dynamic-link library (DLL) file into the app...Show more
A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to execute arbitrary code. By placing a crafted dynamic-link library (DLL) file into the application search path prior to the legitimate library, the malicious code is loaded and executed under the security privileges of the GV-ASManager process.Show less
-
-
Sep 9, 2026
Aug 4, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity...Show more
The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.Show less
-
-
Sep 9, 2026
Aug 4, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity...Show more
The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.Show less
1Microsoft
7Windows 10 1607
Windows 10 1809Windows Server 2012+4 more
Sep 9, 2026
Sep 8, 2026
N/A· v4
5.7 MEDIUM· v3
N/A· v2
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.
1Microsoft
7Windows 10 1607
Windows 10 1809Windows Server 2012+4 more
Sep 9, 2026
Sep 8, 2026
N/A· v4
5.7 MEDIUM· v3
N/A· v2
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.
1Microsoft
7Windows 10 1607
Windows 10 1809Windows Server 2012+4 more
Sep 9, 2026
Sep 8, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Integer overflow or wraparound in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
1Microsoft
7Windows 10 1607
Windows 10 1809Windows Server 2012+4 more
Sep 9, 2026
Sep 8, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
1Microsoft
7Windows 10 1607
Windows 10 1809Windows Server 2012+4 more
Sep 9, 2026
Sep 8, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network.
1Microsoft
7Windows 10 1607
Windows 10 1809Windows Server 2012+4 more
Sep 9, 2026
Sep 8, 2026
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Missing authentication for critical function in Windows DHCP Server allows an authorized attacker to elevate privileges over a network.
1Microsoft
7Windows 10 1607
Windows 10 1809Windows Server 2012+4 more
Sep 9, 2026
Sep 8, 2026
N/A· v4
5.7 MEDIUM· v3
N/A· v2
Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.
1Microsoft
7Windows 10 1607
Windows 10 1809Windows Server 2012+4 more
Sep 9, 2026
Sep 8, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over a network.
1Misp Project
1Misp
Sep 9, 2026
Sep 7, 2026
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This bypasses the intended role restrictions applied...Show more
Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This bypasses the intended role restrictions applied to neighboring template-management operations. The upload handler accepts arbitrary content with only minimal checks and writes it into app/tmp/files/. A low-privileged or read-only user can therefore repeatedly upload files and consume server disk space without requiring perm_add or perm_template. The fix changes the ACL requirement from * to perm_add. The commit also rules out stronger impacts: uploaded files receive random names, path traversal/predictable overwrite is not available, the temporary directory is outside the web root, and the files are not directly served over HTTP. Therefore, the issue should not be described as arbitrary file overwrite, stored XSS, or RCE. Version affected: ≤2.5.45Show less
1Misp Project
1Misp
Sep 9, 2026
Sep 7, 2026
5.1 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /. That check is insufficient because protocol-relative URLs such as //attacker.example also begin...Show more
Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /. That check is insufficient because protocol-relative URLs such as //attacker.example also begin with / but resolve to an external origin in browsers. The vulnerable homepage value can be stored as a user setting and later used by the post-login routing logic. The commit explicitly identifies //attacker.example as a payload that passed validation and was emitted to the Location header after login. The fix introduces a shared InternalRedirectValidator that rejects URLs containing a host, scheme, userinfo, unsafe leading // or /\, malformed URLs, and control characters. It also revalidates homepage settings on read so legacy or internally written unsafe values cannot bypass the new storage-time validation. Version affected: ≤2.5.45Show less