Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 226–250 of 2,372 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18924 | NONE | — | 2026-09-06 | A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup… | |
| CVE-2026-18931 | CRITICAL | 9.1 | 2026-09-01 | Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Retrieve Embedded Sensitive Data. Th… | |
| CVE-2026-18957 | MEDIUM | Patched | 5.4 | 2026-09-04 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software Inc. Menulux Portal allows Stored XSS. This issue af… |
| CVE-2026-18986 | MEDIUM | Patched | 4.8 | 2026-09-02 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. This issue affects Entity Bro… |
| CVE-2026-19032 | MEDIUM | Patched | 5.3 | 2026-09-01 | jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.dese… |
| CVE-2026-19043 | MEDIUM | Patched | 4.3 | 2026-09-04 | Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Menulux Por… |
| CVE-2026-19051 | HIGH | Patched | 7.1 | 2026-09-04 | Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data. This issue affects Menulux Portal: before 20… |
| CVE-2026-19057 | MEDIUM | Patched | 5.4 | 2026-09-04 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Stored XSS. … |
| CVE-2026-19080 | HIGH | Patched | 7.5 | 2026-09-04 | Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting. This issue affects Menulux Portal: before 20260903211448. |
| CVE-2026-19081 | MEDIUM | Patched | 4.3 | 2026-09-04 | Missing Authorization vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affect… |
| CVE-2026-19116 | HIGH | Patched | 8.8 | 2026-09-02 | The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend edit… |
| CVE-2026-19117 | CRITICAL | 9.8 | 2026-09-02 | Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects … | |
| CVE-2026-19118 | HIGH | Patched | 7.5 | 2026-09-01 | A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticat… |
| CVE-2026-19203 | NONE | — | 2026-09-08 | A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, poten… | |
| CVE-2026-19204 | NONE | — | 2026-09-07 | A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exha… | |
| CVE-2026-19205 | HIGH | Patched | 7.5 | 2026-09-04 | Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting. This issue affects GastroMenum Web Panel: before 31.08.2026. |
| CVE-2026-19219 | HIGH | 8.1 | 2026-09-02 | In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attac… | |
| CVE-2026-19224 | HIGH | Patched | 7.2 | 2026-09-04 | The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site… |
| CVE-2026-19251 | MEDIUM | Patched | 5.3 | 2026-09-02 | The Ultimate Member WordPress plugin before 2.13.0 does not check whether a comment has been approved, or whether the profile it belongs to is private, before returning pr… |
| CVE-2026-19274 | CRITICAL | 9.6 | 2026-09-04 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently dest… | |
| CVE-2026-19283 | HIGH | 7.7 | 2026-09-04 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information… | |
| CVE-2026-19298 | HIGH | 8.8 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process. | |
| CVE-2026-19299 | MEDIUM | 6.5 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal. | |
| CVE-2026-19300 | HIGH | 7.5 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields. | |
| CVE-2026-19301 | MEDIUM | 5.0 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery. |