| SonicWall SMA1000 Appliances OS Command Injection Vulnerability CVE-2026-83549 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules | vulnerability 2 exploit 1 | — | 7.8 | 2026-09-01 |
| util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection CVE-2026-78410 · Red Hat | vulnerability 1 | high | 7.8 | 2026-09-02 |
| A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components to permanently fail until an administrator repairs the underlying data. Only the targeted repository is affected; other repositories and overall server health remain unaffected. CVE-2026-77121 · NVD | vulnerability 1 | — | 6.5 | 2026-09-02 |
| SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability CVE-2026-83548 · CISA Known Exploited Vulnerabilities, Metasploit exploit modules | vulnerability 1 exploit 1 | — | — | 2026-09-01 |
| PodcastGenerator 3.2.9 - Stored XSS CVE-2025-70336 · Exploit-DB | exploit 1 | — | — | 2026-09-02 |
| A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens CVE-2025-54957 · Write-ups | article 2 | — | — | 2026-01-14 |
| util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks CVE-2026-78409 · Red Hat | vulnerability 1 | high | 7 | 2026-09-02 |
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. This issue affects Slick Carousel versions: from 0.0.0 to 2.1.0. CVE-2026-81160 · NVD | vulnerability 1 | — | 6.1 | 2026-09-02 |
| SPIP Autosave Session Unauthenticated RCE · Metasploit exploit modules | exploit 1 | — | — | 2026-08-30 |
| Marimo Remote Code Execution Vulnerability CVE-2026-39987 · CISA Known Exploited Vulnerabilities, Exploit-DB | vulnerability 1 exploit 1 | — | — | 2026-04-23 |
| On the Effectiveness of Mutational Grammar Fuzzing · Write-ups | article 1 | — | — | 2026-03-05 |
| Sangoma Switchvox SQL Injection Vulnerability CVE-2026-9586 · CISA Known Exploited Vulnerabilities | vulnerability 1 | — | — | 2026-09-02 |
| util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority CVE-2026-78408 · Red Hat | vulnerability 1 | high | 7.9 | 2026-09-02 |
| Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0. CVE-2026-81158 · NVD | vulnerability 1 | — | 5.3 | 2026-09-02 |
| Langflow AI authenticated RCE CVE-2026-19295 · Metasploit exploit modules | exploit 1 | — | — | 2026-08-28 |
| IBM Langflow Code Injection Vulnerability CVE-2026-9198 · CISA Known Exploited Vulnerabilities, Exploit-DB, Metasploit exploit modules | vulnerability 1 exploit 2 | — | — | 2026-07-17 |
| A Deep Dive into the GetProcessHandleFromHwnd API CVE-2023-41772 · Write-ups | article 1 | — | — | 2026-02-26 |
| JFrog Artifactory Improper Authentication Vulnerability CVE-2026-82329 · CISA Known Exploited Vulnerabilities | vulnerability 1 | — | — | 2026-09-02 |
| util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks CVE-2026-76642 · Red Hat, NVD | vulnerability 2 | high | 7.8 | 2026-09-02 |
| SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist that explicitly permits the onload event handler on iframe elements. Attackers can store crafted JavaScript payloads in post content that execute when the affected post is viewed or previewed by higher-privileged users, potentially leading to privilege escalation or account compromise. CVE-2026-75134 · NVD | vulnerability 1 | — | 6.4 | 2026-09-02 |
| Langflow AI Custom Component Authenticated RCE CVE-2026-18729 · Metasploit exploit modules | exploit 1 | — | — | 2026-08-28 |
| Ghost_CMS 6.19.0 - Remote Code Execution CVE-2026-29053 · Exploit-DB, Metasploit exploit modules | exploit 2 | — | — | 2026-03-02 |
| Bypassing Administrator Protection by Abusing UI Access · Write-ups | article 1 | — | — | 2026-02-12 |
| Kestra OSS OS Command Injection Vulnerability CVE-2026-49869 · CISA Known Exploited Vulnerabilities | vulnerability 1 | — | — | 2026-09-02 |
| grafana: Grafana: SQL Data Source Plugin: OOM DoS via $__timeGroup macro CVE-2026-19475 · Red Hat | vulnerability 1 | medium | 6.5 | 2026-09-02 |