1w ago
2026-09-01 22:17Z
CRIT

CVE-2026-84637 — Malicious: calendar invitations could use file URI attachments to launch local or network-hosted executables

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84637

Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDMaliciousTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-01 22:17Z
CRIT

CVE-2026-84372 — Predis: From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84372

Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggregateConnection::write() by splitting it with explode("\r\n") instead of honoring RESP length prefixes. Attacker-controlled keys or values containing CRLF sequences can therefore be interpreted by Command::deserializeCommand() as additi CVSSv3.1 9.8 (CRITICAL)

CWECWE 93VNDPredisTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-01 22:17Z
HIGH

CVE-2026-83549 — Sonicwall Sma8200v: Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83549in the wild

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. CVSSv3.1 7.8 (HIGH) · EPSS 58th percentile

CWECWE 78VNDSonicwallVNDPostTYPVulnerabilitySTAitw exploited
7.8
CVSS v3.1
89
Edit Score
1w ago
2026-09-01 22:17Z
CRIT

CVE-2026-83548 — Pre: A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83548

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations. CVSSv3.1 10.0 (CRITICAL)

CWECWE 918CWECWE 441VNDPreTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
1w ago
2026-09-01 22:17Z
HIGH

CVE-2026-76851 — Github Enterprise_server: A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76851

A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance. Insufficient network isolation allowed malicious pre-receive hook code to impersonate an internal service and redirect trusted internal requests to a privileged service, leading to elevated code execution. Exploitation required pre-receive hook networking to be enabled and either site administrator privileges or write access to a re CVSSv3.1 8.8 (HIGH) · EPSS 37th percentile

CWECWE 918VNDGithubTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-01 22:17Z
CRIT

CVE-2026-75604 — Next: Disclosure of that key can enable remote code execution in the affected application.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75604

Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in route segments before constructing incremental-cache paths. In packages/next/src/shared/lib/router/utils/escape-path-delimiters.ts and packages/next/src/server/lib/incremental-cache/file-system-cache.ts, a remote request can CVSSv3.1 9.0 (CRITICAL)

CWECWE 22TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
1w ago
2026-09-01 22:17Z
CRIT

CVE-2023-54391 — Proxmox: Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2023-54391

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification CVSSv3.1 9.8 (CRITICAL)

CWECWE 304VNDProxmoxTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2w ago
2026-09-01 21:18Z
HIGH

CVE-2026-84370 — SVGO: When an application processes attacker-controlled SVG input and serves the result in an active

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84370

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions 2 and 3, incompletely filters executable links in plugins/removeScripts.js and lib/svgo/tools.js. The plugin does not recognize namespace-prefixed SVG anchor elements such as svg:a with href or namespaced *:href values, and it does not remove CVSSv3.1 8.2 (HIGH)

CWECWE 79CWECWE 184VNDSvgoTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 21:18Z
HIGH

CVE-2026-73782 — A format string vulnerability exists in the command line interface of AOS-CX that could

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73782

A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 21:18Z
HIGH

CVE-2026-73781 — A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73781

A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. CVSSv3.1 8.4 (HIGH)

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2w ago
2026-09-01 21:18Z
HIGH

CVE-2026-73780 — A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73780

A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against the affected interface if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL. CVSSv3.1 8.3 (HIGH)

TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2w ago
2026-09-01 21:18Z
HIGH

CVE-2026-73779 — Vulnerabilities: have been identified in the operating system of AOS-CX switches that could potentially

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73779

Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could compromise system integrity and further expose sensitive information. CVSSv3.1 8.2 (HIGH)

VNDVulnerabilitiesTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 21:18Z
HIGH

CVE-2026-73778 — Credential: A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73778

A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured credentials by providing a predictable factory-default password. Successful exploitation could result in full administrative control of the affected device during the initial setup process. CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 21:18Z
HIGH

CVE-2026-73777 — Vulnerabilities: have been identified in the API endpoint of AOS-CX switches that could potentially

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73777

Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. CVSSv3.1 8.1 (HIGH)

VNDVulnerabilitiesTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 21:18Z
HIGH

CVE-2026-73753 — Exploitation: through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73753

Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system. CVSSv3.1 8.8 (HIGH)

VNDExploitationTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 21:18Z
HIGH

CVE-2026-73752 — An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73752

An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 21:18Z
HIGH

CVE-2026-73751 — An authenticated user with low-privileged access could submit crafted input through the web-based management

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73751

An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 21:18Z
HIGH

CVE-2026-73750 — Vulnerabilities: exist in the authentication module that may improperly process malformed or truncated input.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73750

Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful exploitation could result in a Denial-of-Service or potential remote code execution with elevated privileges. CVSSv3.1 8.8 (HIGH)

VNDVulnerabilitiesTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 21:18Z
CRIT

CVE-2026-73749 — Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73749

Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges. CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 21:18Z
HIGH

CVE-2026-71981 — Cypht: before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71981

Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted PHP object graph in the back_query GET parameter of the logout handler. Attackers can pass a base64-encoded serialized payload through this parameter, which is decoded and passed directly to unserialize() without an allow-list, signature check, or type restriction, enabling gadget-chain exploitation to achi CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDCyphtTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 20:17Z
CRIT

CVE-2026-76658 — A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76658

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise. CVSSv3.1 10.0 (CRITICAL)

TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2w ago
2026-09-01 20:17Z
CRIT

CVE-2026-76657 — Vulnerabilities: have been identified in the API of HPE Networking Fabric Composer that could

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76657

Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host. CVSSv3.1 10.0 (CRITICAL)

VNDVulnerabilitiesTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2w ago
2026-09-01 20:17Z
HIGH

CVE-2026-73712 — API: A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73712

A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise. CVSSv3.1 8.1 (HIGH)

VNDApiTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 20:17Z
HIGH

CVE-2026-73711 — A privilege escalation vulnerability exists in the API endpoint of HPE Networking Fabric Composer.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73711

A privilege escalation vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated remote attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host. CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 20:17Z
HIGH

CVE-2026-73710 — Vulnerabilities: in an API endpoint of HPE Networking Fabric Composer could allow an unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73710

Vulnerabilities in an API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to make limited unauthorized modifications to the underlying operating system and disrupt the availability of the affected system, requiring manual intervention to restore functionality. CVSSv3.1 8.2 (HIGH)

VNDVulnerabilitiesTYPVulnerability
8.2
CVSS v3.1
91
Edit Score