boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, September 1, 2026 · all times UTC← 2026-08-31 · archive

Security Box Score — September 1, 2026 — page 2

Edition of September 1, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–477 of 477
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-737472.5—Hewlett Packard Enterprise (HPE)Fabric ComposerCWE-269Local Privilege Escalation Vulnerability in HPE Networking Fabric Composer
CVE-2026-737482.2—Hewlett Packard Enterprise (HPE)Fabric ComposerCWE-312Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer
CVE-2026-840592.1—ICP DASUA-2200CWE-74ICP DAS UA-2200/UA-5200 CGI ArmAngstromInstructionSet command injection
CVE-2026-841092.1—XinhuRainrock RockOACWE-74Xinhu Rainrock RockOA webmainAction.php getOrder sql injection
CVE-2026-841142.1—CleoHarmonyCWE-287Cleo Harmony SAML Authentication LocalUserUtil.getNativeUserByAssertions impr…
CVE-2026-841532.1—XinhuRainrock RockOACWE-74Xinhu Rainrock RockOA index.php toaddval sql injection
CVE-2026-842872.1—NousResearchhermes-agentCWE-404NousResearch hermes-agent Session Chat api_server.py denial of service
CVE-2026-842882.1—NousResearchhermes-agentCWE-404NousResearch hermes-agent ACP Prompt Workflow session.py HermesACPAgent.promp…
CVE-2026-842892.1—NousResearchhermes-agentCWE-400NousResearch hermes-agent MCP Tool mcp_tool.py list_tools memory allocation
CVE-2026-19590await—OpenAICodex DesktopCWE-427OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled …
CVE-2026-19591await—OpenAICodex CLICWE-150OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows …
CVE-2026-19592await—OpenAICodex CLICWE-15OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows …
CVE-2026-19593await—OpenAICodex DesktopCWE-15OpenAI Codex Desktop for Windows and macOS automatically inspected Git metada…
CVE-2026-51741await—n/an/a—Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1…
CVE-2026-51744await—n/an/a—Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4…
CVE-2026-51747await—n/an/a—Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748…
CVE-2026-51750await—n/an/a—Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.…
CVE-2026-51751await—n/an/a—Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5c…
CVE-2026-51754await—n/an/a—Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1…
CVE-2026-51757await—n/an/a—Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5…
CVE-2026-51760await—n/an/a—Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5…
CVE-2026-51762await—n/an/a—Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.…
CVE-2026-51763await—n/an/a—Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu…
CVE-2026-51764await—n/an/a—Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLIN…
CVE-2026-51765await—n/an/a—Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 …
CVE-2026-51767await—n/an/a—Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.…
CVE-2026-51768await—n/an/a—Incorrect access control in the setElinkQosConfig function of TOTOLINK T6 4.1…
CVE-2026-51769await—n/an/a—Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T…
CVE-2026-51770await—n/an/a—Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6…
CVE-2026-51788await—n/an/a—An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a deni…
CVE-2026-51934await—n/an/a—Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co., Ltd.…
CVE-2026-51956await—n/an/a—A Broken Object Level Authorization vulnerability exists in Grashjs Atlas CMM…
CVE-2026-51974await—n/an/a—An eval() injection vulnerability in the get_list function in modules/meta_pa…
CVE-2026-52022await—n/an/a—An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a d…
CVE-2026-52023await—n/an/a—An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a d…
CVE-2026-52111await—n/an/a—An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escal…
CVE-2026-52131await—n/an/a—llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::rea…
CVE-2026-52132await—n/an/a—llama.cpp through commit 97f06e9, when started with the --reranking flag, all…
CVE-2026-52295await—n/an/a—Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows an attacker to…
CVE-2026-80047await—Hugging FaceTransformers—Hugging Face Transformers library writes remote code to disk prior to consent…
CVE-2026-81928await——Net-DNSCWE-674Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded …
CVE-2026-83548await—SonicWallSMA1000CWE-441A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work …
CVE-2026-84129await—MozillaFirefox—Site isolation issue in the DOM: Navigation component
CVE-2026-84130await—MozillaFirefox—Information disclosure in the Graphics: WebGPU component
CVE-2026-84132await—MozillaFirefox—Information disclosure in the Networking: HTTP component
CVE-2026-84133await—MozillaFirefox—Site isolation issue in the DOM: Push Subscriptions component
CVE-2026-84134await—MozillaFirefox—Other issue in the Profile Backup component
CVE-2026-84135await—MozillaFirefox—Other issue in Firefox Focus for Android
CVE-2026-84136await—MozillaFirefox—Other issue in the DOM: Navigation component
CVE-2026-84137await—MozillaFirefox—Spoofing issue in the DOM: Core & HTML component
CVE-2026-84138await—MozillaFirefox—Denial-of-service in the PDF Viewer component
CVE-2026-84139await—MozillaFirefox—Clickjacking issue in the DOM: Events component
CVE-2026-84140await—MozillaFirefox—Site isolation issue in the DOM: Navigation component
CVE-2026-84141await—MozillaFirefox—Integer overflow in the Graphics: ImageLib component
CVE-2026-84142await—MozillaFirefox—Internally found bugs fixed in Thunderbird 155
CVE-2026-84143await—MozillaFirefox—Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thu…
CVE-2026-84144await—MozillaFirefox—Internally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.2
CVE-2026-84325await—GoogleChromeCWE-20Improper input validation in DataTransfer in Google Chrome prior to 152.0.797…
CVE-2026-84326await—GoogleChromeCWE-908Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed …
CVE-2026-84328await—GoogleChromeCWE-862Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 a…
CVE-2026-84330await—GoogleChromeCWE-451UI misrepresentation in FullScreen in Google Chrome on on Android prior to 15…
CVE-2026-84331await—GoogleChromeCWE-863Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allo…
CVE-2026-84332await—GoogleChromeCWE-863Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.…
CVE-2026-84349await—GoogleChromeCWE-416Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a r…
CVE-2026-84352await—GoogleChromeCWE-416Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75…
CVE-2026-84353await—GoogleChromeCWE-416Use after free in Shared Tab Groups in Google Chrome on on Android prior to 1…
CVE-2026-84354await—GoogleChromeCWE-863Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75…
CVE-2026-84355await—GoogleChromeCWE-863Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75…
CVE-2026-84356await—GoogleChromeCWE-451UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 al…
CVE-2026-84357await—GoogleChromeCWE-20Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 …
CVE-2026-84358await—GoogleChromeCWE-269Improper privilege management in Downloads in Google Chrome prior to 152.0.79…
CVE-2026-84359await—GoogleChromeCWE-200Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a re…
CVE-2026-84637await—MozillaThunderbird—Calendar invitation attachments could launch local executables
CVE-2026-84639await—MozillaThunderbird—Uninitialized memory in MIME parsing
CVE-2026-84640await—MozillaThunderbird—One byte overflow read in mail parser
CVE-2026-84641await—MozillaThunderbird—Information disclosure due to malicious IMAP server response
CVE-2026-84642await—MozillaThunderbird—Allowed UNC hostnames for attachments interpreted as a regular expression