Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 2 September 2026

RSS

774 vulnerabilities published on 2 September 2026

Severity:
Embed HTML5 Game plugin up to 1.3 allows file upload
CVE-2026-4357
The Embed HTML5 Game plugin for WordPress, versions up through 1.3, does not check who is uploading files or what type of file is allowed. Because of that, a stranger could place a malicious script on...
10.0
WatchMan‑Site7 plugin lets logged‑in users run code on server
CVE-2026-77009
The WatchMan‑Site7 add‑on for WordPress (versions 3.1.1 through 4.2.0) leaves its debug console open to anyone with a basic account. That means a regular user can enter code that the server will execu...
9.9
On‑premises server lets attacker add fake FIDO2 login
CVE-2026-19117
If you run the software on your own servers, a flaw can let a malicious person create a fake security key for a user’s account and then sign in as that user. This could give an attacker access to the ...
9.8
Cisco IOS XR may let unauthorized users access protected features
CVE-2026-20279
Cisco’s IOS XR operating system contains several access‑control gaps that could let someone without proper rights reach functions they shouldn’t. This could expose configuration data or allow changes ...
9.8
Cisco IOS XR may let attackers exhaust system resources
CVE-2026-20274
The Cisco IOS XR operating system used in many network routers has been updated to fix several internal weaknesses that could let a malicious user consume the device’s memory or processing power. If e...
9.8
Cisco Nexus 9000 Switches can be remotely taken over
CVE-2026-20212
The Silicon One integration on Cisco Nexus 9000 series switches listens on two network ports that are open by default. An attacker on the network could connect to those ports, send specially crafted d...
9.8
Looking Glass before 1.3.5 allows remote code execution
CVE-2026-53611
The Looking Glass tool (versions earlier than 1.3.5) can be tricked into running unauthorized commands on the server because it does not properly check certain input. This could let an attacker take c...
9.8
Webpack Loader-Utils Allows Arbitrary Function Execution
GHSA-76p3-8jx3-jpfq CVE-2022-37601 ROOT-APP-NPM-CVE-2022-37601
A security issue in Webpack Loader-Utils allows attackers to execute arbitrary JavaScript code. This affects all versions before 1.4.1 and 2.0.3. To fix this issue, update to version 1.4.1 or 2.0.3 or...
9.8
Flatted: Unvalidated JSON Keys Can Pollute Global Prototype
DEBIAN-CVE-2026-33228 ROOT-APP-NPM-CVE-2026-33228 GHSA-rf6f-7fwh-wjgh CVE-2026-33228
Prior to version 3.4.2, Flatted's parse function did not properly check the validity of JSON keys, potentially allowing an attacker to manipulate the global prototype. This could lead to unexpected be...
8.9
SeaweedFS: Unauthenticated access to S3 admin controls
CVE-2026-72920 BIT-seaweedfs-2026-72920 GHSA-2v6v-25fm-p4fg
SeaweedFS, a distributed storage system, has a security issue that allows unauthorized users to gain full control over S3 settings. This could lead to data being deleted or modified without permission...
9.8
Grav before 2.0.7 allows attackers to run malicious code
CVE-2026-65008 CVE-2026-64850 GHSA-fj2p-qj2f-74v5
A security flaw in Grav, a content management system, allows an attacker with administrative access to inject and run malicious code on a website. This could happen even if the attacker is not logged ...
9.9
Developer Tools plugin lets anyone upload files
CVE-2025-9314
The WordPress Developer Tools plugin (versions up to 1.1.3) allows anyone on the internet to place files onto your site without logging in, using a built‑in upload feature. This could let attackers ad...
9.8
Craft CMS lets new users inherit admin rights
CVE-2026-84795
Versions of Craft CMS older than 5.10.11 can let a person sign up using the email address of a former administrator and automatically receive admin privileges, but only when public registration is all...
9.2
Authorizer up to 3.15.1 lets anyone gain admin rights
CVE-2026-81294
Versions of the Authorizer product up to 3.15.1 allow a person without any credentials to elevate their access to full administrative control. This means an attacker could change settings, view or del...
9.8
Rollup 4 Allows Attackers to Write to Any File on Your Computer
DEBIAN-CVE-2026-27606 CVE-2026-27606 GHSA-mw96-cpmx-2vgc ROOT-APP-NPM-CVE-2026-27606
If you use Rollup version 4, an attacker could potentially write to any file on your computer that your build process has access to. This could allow them to take control of your system or user settin...
9.1
immer library allows attackers to modify sensitive data
GHSA-c36v-fmgq-m8hx CVE-2021-3757 ROOT-APP-NPM-CVE-2021-3757
The immer library has a security flaw that lets attackers change how data is stored in a way that's not supposed to be changed. This could lead to unexpected behavior in your code. To stay secure, upd...
9.8
SigmaForms Pro plugin can let attackers delete any file
CVE-2026-78657
All versions of the SigmaForms Pro – AI Generated Forms plugin for WordPress up through 1.4.11 let anyone send a specially crafted request that makes the site delete files it shouldn't. This could rem...
9.8
jsonpath: Malicious Code Can Run on Your Server
CVE-2026-1615 GHSA-87r5-mp6g-5w5j ROOT-APP-NPM-CVE-2026-1615
The jsonpath library has a security flaw that allows hackers to run malicious code on your server. This can happen if you use the library to evaluate user input and don't properly check what's being p...
8.2
Amelia WordPress plugin lets attackers become admins
CVE-2026-9055
The Amelia booking plugin for WordPress (versions 8.0 through 9.6.2) lets anyone change their account to a manager and then take over an administrator’s account. This happens because the plugin does n...
9.8
Google Chrome <152 can be tricked to bypass limits
CVE-2026-84325
Versions of Google Chrome released before 152 may let a malicious website convince a user to install a companion app that then sidesteps normal security checks. This could let an attacker gain access ...
9.8
OpenChoreo: Unauthenticated access to data-plane operations
CVE-2026-73843 GHSA-qh9r-j7rp-4x2m
A security issue in OpenChoreo, a developer platform for Kubernetes, allowed attackers to access sensitive data and execute commands in workload pods without a password. This issue has been fixed in v...
9.6
Klever-Go before 1.7.19 may create unbacked tokens
GHSA-p7gw-2pcp-5pf8 CVE-2026-54754 GO-2026-6315
If you run Klever-Go version earlier than 1.7.19, a seller can manipulate referral and royalty settings so the system pays out more tokens than were actually bought. This can inflate the token supply ...
9.6
Joro: Unauthenticated Plugin Upload Allows Remote Code Execution
GHSA-xqhv-chqm-fhcc CVE-2026-53649
Joro's default proxy mode allows attackers to upload malicious plugins and execute code on the system without a password. This can happen when a user visits a website with malicious JavaScript. To fix...
9.6
Google Chrome before version 152 may run code from malicious web page
CVE-2026-84354
Older versions of Google Chrome (earlier than 152.0.7977.75) can be tricked by a carefully crafted web page to run code on the computer, bypassing Chrome’s normal safety sandbox. An attacker would nee...
9.6
Google Chrome Android before 152 can run malicious code
CVE-2026-84353
Chrome on Android versions older than 152 may let a specially crafted web page run unauthorized code on the device. This can happen if a user is tricked into opening a malicious page, potentially bypa...
9.6