Security Box Score — September 1, 2026 — page 2
Edition of September 1, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-73747 | 2.5 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | CWE-269 | Local Privilege Escalation Vulnerability in HPE Networking Fabric Composer |
| CVE-2026-73748 | 2.2 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | CWE-312 | Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer |
| CVE-2026-84059 | 2.1 | — | ICP DAS | UA-2200 | CWE-74 | ICP DAS UA-2200/UA-5200 CGI ArmAngstromInstructionSet command injection |
| CVE-2026-84109 | 2.1 | — | Xinhu | Rainrock RockOA | CWE-74 | Xinhu Rainrock RockOA webmainAction.php getOrder sql injection |
| CVE-2026-84114 | 2.1 | — | Cleo | Harmony | CWE-287 | Cleo Harmony SAML Authentication LocalUserUtil.getNativeUserByAssertions impr… |
| CVE-2026-84153 | 2.1 | — | Xinhu | Rainrock RockOA | CWE-74 | Xinhu Rainrock RockOA index.php toaddval sql injection |
| CVE-2026-84287 | 2.1 | — | NousResearch | hermes-agent | CWE-404 | NousResearch hermes-agent Session Chat api_server.py denial of service |
| CVE-2026-84288 | 2.1 | — | NousResearch | hermes-agent | CWE-404 | NousResearch hermes-agent ACP Prompt Workflow session.py HermesACPAgent.promp… |
| CVE-2026-84289 | 2.1 | — | NousResearch | hermes-agent | CWE-400 | NousResearch hermes-agent MCP Tool mcp_tool.py list_tools memory allocation |
| CVE-2026-19590 | await | — | OpenAI | Codex Desktop | CWE-427 | OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled … |
| CVE-2026-19591 | await | — | OpenAI | Codex CLI | CWE-150 | OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows … |
| CVE-2026-19592 | await | — | OpenAI | Codex CLI | CWE-15 | OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows … |
| CVE-2026-19593 | await | — | OpenAI | Codex Desktop | CWE-15 | OpenAI Codex Desktop for Windows and macOS automatically inspected Git metada… |
| CVE-2026-51741 | await | — | n/a | n/a | — | Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1… |
| CVE-2026-51744 | await | — | n/a | n/a | — | Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4… |
| CVE-2026-51747 | await | — | n/a | n/a | — | Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748… |
| CVE-2026-51750 | await | — | n/a | n/a | — | Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.… |
| CVE-2026-51751 | await | — | n/a | n/a | — | Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5c… |
| CVE-2026-51754 | await | — | n/a | n/a | — | Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1… |
| CVE-2026-51757 | await | — | n/a | n/a | — | Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5… |
| CVE-2026-51760 | await | — | n/a | n/a | — | Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5… |
| CVE-2026-51762 | await | — | n/a | n/a | — | Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.… |
| CVE-2026-51763 | await | — | n/a | n/a | — | Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu… |
| CVE-2026-51764 | await | — | n/a | n/a | — | Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLIN… |
| CVE-2026-51765 | await | — | n/a | n/a | — | Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 … |
| CVE-2026-51767 | await | — | n/a | n/a | — | Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.… |
| CVE-2026-51768 | await | — | n/a | n/a | — | Incorrect access control in the setElinkQosConfig function of TOTOLINK T6 4.1… |
| CVE-2026-51769 | await | — | n/a | n/a | — | Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T… |
| CVE-2026-51770 | await | — | n/a | n/a | — | Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6… |
| CVE-2026-51788 | await | — | n/a | n/a | — | An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a deni… |
| CVE-2026-51934 | await | — | n/a | n/a | — | Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co., Ltd.… |
| CVE-2026-51956 | await | — | n/a | n/a | — | A Broken Object Level Authorization vulnerability exists in Grashjs Atlas CMM… |
| CVE-2026-51974 | await | — | n/a | n/a | — | An eval() injection vulnerability in the get_list function in modules/meta_pa… |
| CVE-2026-52022 | await | — | n/a | n/a | — | An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a d… |
| CVE-2026-52023 | await | — | n/a | n/a | — | An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a d… |
| CVE-2026-52111 | await | — | n/a | n/a | — | An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escal… |
| CVE-2026-52131 | await | — | n/a | n/a | — | llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::rea… |
| CVE-2026-52132 | await | — | n/a | n/a | — | llama.cpp through commit 97f06e9, when started with the --reranking flag, all… |
| CVE-2026-52295 | await | — | n/a | n/a | — | Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows an attacker to… |
| CVE-2026-80047 | await | — | Hugging Face | Transformers | — | Hugging Face Transformers library writes remote code to disk prior to consent… |
| CVE-2026-81928 | await | — | — | Net-DNS | CWE-674 | Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded … |
| CVE-2026-83548 | await | — | SonicWall | SMA1000 | CWE-441 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work … |
| CVE-2026-84129 | await | — | Mozilla | Firefox | — | Site isolation issue in the DOM: Navigation component |
| CVE-2026-84130 | await | — | Mozilla | Firefox | — | Information disclosure in the Graphics: WebGPU component |
| CVE-2026-84132 | await | — | Mozilla | Firefox | — | Information disclosure in the Networking: HTTP component |
| CVE-2026-84133 | await | — | Mozilla | Firefox | — | Site isolation issue in the DOM: Push Subscriptions component |
| CVE-2026-84134 | await | — | Mozilla | Firefox | — | Other issue in the Profile Backup component |
| CVE-2026-84135 | await | — | Mozilla | Firefox | — | Other issue in Firefox Focus for Android |
| CVE-2026-84136 | await | — | Mozilla | Firefox | — | Other issue in the DOM: Navigation component |
| CVE-2026-84137 | await | — | Mozilla | Firefox | — | Spoofing issue in the DOM: Core & HTML component |
| CVE-2026-84138 | await | — | Mozilla | Firefox | — | Denial-of-service in the PDF Viewer component |
| CVE-2026-84139 | await | — | Mozilla | Firefox | — | Clickjacking issue in the DOM: Events component |
| CVE-2026-84140 | await | — | Mozilla | Firefox | — | Site isolation issue in the DOM: Navigation component |
| CVE-2026-84141 | await | — | Mozilla | Firefox | — | Integer overflow in the Graphics: ImageLib component |
| CVE-2026-84142 | await | — | Mozilla | Firefox | — | Internally found bugs fixed in Thunderbird 155 |
| CVE-2026-84143 | await | — | Mozilla | Firefox | — | Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thu… |
| CVE-2026-84144 | await | — | Mozilla | Firefox | — | Internally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.2 |
| CVE-2026-84325 | await | — | Chrome | CWE-20 | Improper input validation in DataTransfer in Google Chrome prior to 152.0.797… | |
| CVE-2026-84326 | await | — | Chrome | CWE-908 | Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed … | |
| CVE-2026-84328 | await | — | Chrome | CWE-862 | Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 a… | |
| CVE-2026-84330 | await | — | Chrome | CWE-451 | UI misrepresentation in FullScreen in Google Chrome on on Android prior to 15… | |
| CVE-2026-84331 | await | — | Chrome | CWE-863 | Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allo… | |
| CVE-2026-84332 | await | — | Chrome | CWE-863 | Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.… | |
| CVE-2026-84349 | await | — | Chrome | CWE-416 | Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a r… | |
| CVE-2026-84352 | await | — | Chrome | CWE-416 | Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75… | |
| CVE-2026-84353 | await | — | Chrome | CWE-416 | Use after free in Shared Tab Groups in Google Chrome on on Android prior to 1… | |
| CVE-2026-84354 | await | — | Chrome | CWE-863 | Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75… | |
| CVE-2026-84355 | await | — | Chrome | CWE-863 | Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75… | |
| CVE-2026-84356 | await | — | Chrome | CWE-451 | UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 al… | |
| CVE-2026-84357 | await | — | Chrome | CWE-20 | Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 … | |
| CVE-2026-84358 | await | — | Chrome | CWE-269 | Improper privilege management in Downloads in Google Chrome prior to 152.0.79… | |
| CVE-2026-84359 | await | — | Chrome | CWE-200 | Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a re… | |
| CVE-2026-84637 | await | — | Mozilla | Thunderbird | — | Calendar invitation attachments could launch local executables |
| CVE-2026-84639 | await | — | Mozilla | Thunderbird | — | Uninitialized memory in MIME parsing |
| CVE-2026-84640 | await | — | Mozilla | Thunderbird | — | One byte overflow read in mail parser |
| CVE-2026-84641 | await | — | Mozilla | Thunderbird | — | Information disclosure due to malicious IMAP server response |
| CVE-2026-84642 | await | — | Mozilla | Thunderbird | — | Allowed UNC hostnames for attachments interpreted as a regular expression |