Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 226–250 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-18924 NONE — 2026-09-06 A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup…
CVE-2026-18931 CRITICAL 9.1 2026-09-01 Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Retrieve Embedded Sensitive Data. Th…
CVE-2026-18957 MEDIUM Patched 5.4 2026-09-04 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software Inc. Menulux Portal allows Stored XSS. This issue af…
CVE-2026-18986 MEDIUM Patched 4.8 2026-09-02 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. This issue affects Entity Bro…
CVE-2026-19032 MEDIUM Patched 5.3 2026-09-01 jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.dese…
CVE-2026-19043 MEDIUM Patched 4.3 2026-09-04 Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Menulux Por…
CVE-2026-19051 HIGH Patched 7.1 2026-09-04 Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data. This issue affects Menulux Portal: before 20…
CVE-2026-19057 MEDIUM Patched 5.4 2026-09-04 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Stored XSS. …
CVE-2026-19080 HIGH Patched 7.5 2026-09-04 Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting. This issue affects Menulux Portal: before 20260903211448.
CVE-2026-19081 MEDIUM Patched 4.3 2026-09-04 Missing Authorization vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affect…
CVE-2026-19116 HIGH Patched 8.8 2026-09-02 The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend edit…
CVE-2026-19117 CRITICAL 9.8 2026-09-02 Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects …
CVE-2026-19118 HIGH Patched 7.5 2026-09-01 A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticat…
CVE-2026-19203 NONE — 2026-09-08 A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, poten…
CVE-2026-19204 NONE — 2026-09-07 A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exha…
CVE-2026-19205 HIGH Patched 7.5 2026-09-04 Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting. This issue affects GastroMenum Web Panel: before 31.08.2026.
CVE-2026-19219 HIGH 8.1 2026-09-02 In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attac…
CVE-2026-19224 HIGH Patched 7.2 2026-09-04 The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site…
CVE-2026-19251 MEDIUM Patched 5.3 2026-09-02 The Ultimate Member WordPress plugin before 2.13.0 does not check whether a comment has been approved, or whether the profile it belongs to is private, before returning pr…
CVE-2026-19274 CRITICAL 9.6 2026-09-04 IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently dest…
CVE-2026-19283 HIGH 7.7 2026-09-04 IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information…
CVE-2026-19298 HIGH 8.8 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.
CVE-2026-19299 MEDIUM 6.5 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal.
CVE-2026-19300 HIGH 7.5 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.
CVE-2026-19301 MEDIUM 5.0 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery.