Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 3 September 2026
RSS786 vulnerabilities published on 3 September 2026
Severity:
SiYuan SQL Injection via searchEmbedBlock
CVE-2026-69084
GHSA-vh22-h7hf-www7
SiYuan versions 3.7.2 and earlier are vulnerable to SQL injection attacks. This means that an attacker can potentially access and modify sensitive information in your notebooks. To fix this issue, upd...
9.9
MapLibre GL JS may run malicious code via crafted attribution
CVE-2026-85061
The interactive map library MapLibre GL JS (versions before 6.4.1) can fail to remove dangerous HTML attributes when processing custom attribution text. An attacker who supplies specially crafted attr...
10.0
Go SSH Server Skips Security Checks for Wrong Authentication
DEBIAN-CVE-2026-46595
GO-2026-5023
CVE-2026-46595
GHSA-x527-x647-q7gg
A security check is bypassed in Go SSH servers when using an incorrect authentication method. This allows unauthorized access to the server. To fix this, update your Go SSH server to the latest versio...
10.0
TOTOLINK CP450 router allows remote takeover
CVE-2026-85031
The CP450 router’s web interface contains a flaw that can be triggered by sending a specially crafted request. An attacker could use this to run code on the device from anywhere on the internet. Updat...
9.9
Peppermint up to version 0.5.5 lets attackers fake login tokens
CVE-2026-85391
The container setup file used by Peppermint versions up to 0.5.5 includes a secret key that is publicly visible. Because of this, someone without an account can create a valid login token and access a...
9.3
R2R 3.6.6 lets attackers run database commands
CVE-2026-82526
Versions of R2R up to 3.6.6 let anyone send a specially crafted request to the vector index creation feature and cause the system to execute any database command it wants. Because the request does not...
9.3
JobSearch plugin up to 3.2 lets attackers run code
CVE-2026-84834
The JobSearch add‑on for WordPress, versions 3.2 and older, can be tricked by anyone on the internet into processing harmful data. This could let a malicious user take control of your website without ...
9.8
WordPress Bricksforge plugin lets low-level users gain admin rights
CVE-2026-84814
The Bricksforge add‑on for WordPress, up through version 3.1.8.8, allows a user with the lowest permission level to elevate their rights to full administrator control. This could let an attacker take ...
9.8
Mail Mint plugin can let attackers run code
CVE-2026-84753
The Mail Mint add‑on for WordPress (versions up to 1.31.0) can be tricked into executing unwanted commands without any login. This could let a stranger take control of your site or steal data. Update ...
9.8
YITH Quote Plugin for WooCommerce (versions before 4.46) lets anyone change settings
CVE-2026-84238
The premium YITH "Request a Quote" add‑on for WooCommerce can be accessed without logging in, allowing anyone on the internet to view or modify its configuration. This could let attackers alter how qu...
9.8
Tenda HG10 router login can be crashed remotely
CVE-2026-85109
The login page on Tenda HG10 routers can be tricked into overflowing its memory when a specially crafted username is sent. This could let an attacker disrupt the router or potentially take control. Up...
8.9
CAT 3.1.0 lets attackers create fake admin sessions
CVE-2026-85181
The CAT web tool (up to version 3.1.0) checks session cookies with an insecure method that can be copied and altered without a secret key. Because of this, someone could craft a valid cookie and, by s...
9.3
AVideo lets stolen video token hijack admin account
CVE-2026-85154
The AVideo platform uses a video token that never expires and cannot be revoked. If someone obtains this token, they can log in as the video owner and gain full control, even after the owner changes t...
9.8
libtiff tiffcrop tool can let attackers run code
CVE-2026-52490
ROOT-OS-DEBIAN-12-CVE-2026-52490
DEBIAN-CVE-2026-52490
ROOT-OS-DEBIAN-13-CVE-2026-52490
The libtiff image library, which many programs use to work with TIFF files, has a flaw in its tiffcrop utility that could allow a malicious user to run any program on the affected system. This could l...
9.8
y18n: Malicious data can be written to the global namespace
GHSA-c4w7-xm78-47vh
CVE-2020-7774
ROOT-APP-NPM-CVE-2020-7774
The y18n package, used for internationalization, allows an attacker to inject malicious code into the global scope, potentially leading to unexpected behavior or security issues. This affects develope...
9.8
Apache Zookeeper using Netty may allow data leaks
CLEANSTART-2026-LB53225
The Apache Zookeeper software includes a component called Netty that has several security weaknesses. These could let attackers view or manipulate data passing through Zookeeper. Update Zookeeper to t...
9.8
Apache Zookeeper may allow unauthorized access via Netty
CLEANSTART-2026-JY55743
The Apache Zookeeper software uses the Netty networking library, which contains several security weaknesses. These flaws could let an attacker connect to Zookeeper and potentially read or change data ...
9.8
INI Package Parses Malicious Files, Exposes Application to Further Attacks
GHSA-qqgx-2p2h-9c37
CVE-2020-7788
ROOT-APP-NPM-CVE-2020-7788
The ini package before version 1.3.6 can be exploited by an attacker submitting a malicious INI file, potentially allowing them to compromise the application's security. This can lead to further vulne...
9.8
Chrome on iOS may let malicious page run code
CVE-2026-85047
Versions of the Chrome browser for iPhone and iPad before 152.0.7977.82 could be tricked by a specially crafted web page to run code outside the browser's protected area. This could allow an attacker ...
9.6
Google Chrome <152.0.7977.82 may run malicious code
CVE-2026-85042
Versions of Google Chrome older than 152.0.7977.82 can be tricked by a specially crafted web page to execute code on the computer, bypassing Chrome’s protection. This could let an attacker take contro...
9.6
Chrome for Android can run malicious code via WebGL
CVE-2026-85050
If you use Chrome on Android versions before 152.0.7977.82, a specially crafted web page could cause the browser to write data outside its safe area and let an attacker run code on the device. This co...
9.6
MISP allows login with empty password via LDAP or LinOTP
CVE-2026-85216
MISP’s LDAP and LinOTP login modules do not properly check that a password is supplied. An attacker who knows a valid user’s email address can log in by submitting a blank password, gaining the same a...
9.5
Eclipse Arrowhead 5.0‑5.2.1 permits MQTT takeover
CVE-2026-82180
Eclipse Arrowhead versions 5.0.0 through 5.2.1 let anyone who can publish to the MQTT broker pretend to be the system administrator. The software reads a digital ID sent in the message but never check...
9.5
J2Store Joomla extension can let attackers run code
CVE-2026-78069
Versions of the J2Store extension for Joomla (up to 4.1.6) do not properly check who can use the Apps functions. Because of this, a remote user could cause the system to read or execute files it shoul...
9.5
Ocsreports admin upload can run malicious scripts
CVE-2026-76174
The Ocsreports reporting tool lets administrators upload CSV files, but it only checks the file name, not the actual content. This means a malicious script could be placed on the web server and run wi...
9.4