CVE ID :CVE-2026-84452 Published : Sept. 2, 2026, 8:17 p.m. | 4 hours, 19 minutes ago Description :Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for…
CVE-2026-82524 – UnoPim Arbitrary File Upload Vulnerability
CVE ID :CVE-2026-82524 Published : Sept. 2, 2026, 8:17 p.m. | 4 hours, 19 minutes ago Description :UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP…
CVE-2026-84381 – HTTPX2 SOCKS5 Proxy TLS Upgrade Failure Vulnerability
CVE ID :CVE-2026-84381 Published : Sept. 2, 2026, 7:18 p.m. | 5 hours, 19 minutes ago Description :HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS…
CVE-2026-19117 – FIDO2 Authentication Bypass Vulnerability
CVE ID :CVE-2026-19117 Published : Sept. 2, 2026, 7:17 p.m. | 5 hours, 20 minutes ago Description :Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then…
CVE-2026-66786 – Submariner Configuration Injection Remote Code Execution
CVE ID :CVE-2026-66786 Published : Sept. 2, 2026, 6:21 p.m. | 6 hours, 16 minutes ago Description :A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings…
CVE-2026-84482 – WWBN AVideo Cross-Site Request Forgery via get_domain() validation
CVE ID :CVE-2026-84482 Published : Sept. 1, 2026, 11:17 p.m. | 1 hour, 19 minutes ago Description :WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions…
CVE-2026-84480 – WWBN AVideo Password Recovery Token Expiration Bypass
CVE ID :CVE-2026-84480 Published : Sept. 1, 2026, 11:17 p.m. | 1 hour, 19 minutes ago Description :WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens…
CVE-2026-84479 – WWBN AVideo Authentication Bypass via User-Agent Header
CVE ID :CVE-2026-84479 Published : Sept. 1, 2026, 11:17 p.m. | 1 hour, 19 minutes ago Description :WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent…
CVE-2026-84476 – WWBN AVideo Authentication Bypass via X-Real-IP Header
CVE ID :CVE-2026-84476 Published : Sept. 1, 2026, 11:17 p.m. | 1 hour, 19 minutes ago Description :WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof…
CVE-2026-84208 – AVideo User_Location Plugin Unauthenticated SQL Injection
CVE ID :CVE-2026-84208 Published : Sept. 1, 2026, 11:17 p.m. | 1 hour, 19 minutes ago Description :AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin’s regions.json.php and cities.json.php…