Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 226–250 of 2,372 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-82955 | NONE | — | 2026-09-02 | In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component had the disable_… | |
| CVE-2026-84803 | CRITICAL | 9.0 | 2026-09-02 | SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. A… | |
| CVE-2026-84324 | CRITICAL | Patched | 9.0 | 2026-09-02 | Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromi… |
| CVE-2026-75604 | CRITICAL | Patched | 9.0 | 2026-09-01 | Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without C… |
| CVE-2026-73700 | CRITICAL | Patched | 9.0 | 2026-09-01 | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-s… |
| CVE-2026-73701 | CRITICAL | Patched | 9.0 | 2026-09-01 | An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain precond… |
| CVE-2026-79687 | CRITICAL | 9.0 | 2026-09-01 | Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this v… | |
| CVE-2026-84200 | CRITICAL | Patched | 9.0 | 2026-09-01 | Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive … |
| CVE-2026-67394 | NONE | Patched | — | 2026-09-01 | A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 an… |
| CVE-2026-48019 | HIGH | Patched | 8.9 | 2026-09-04 | Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony… |
| CVE-2026-80515 | NONE | — | 2026-09-03 | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by callin… | |
| CVE-2026-18851 | HIGH | 8.8 | 2026-09-08 | Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges… | |
| CVE-2026-12648 | HIGH | Patched | 8.8 | 2026-09-08 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. |
| CVE-2026-12651 | HIGH | Patched | 8.8 | 2026-09-08 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. |
| CVE-2026-77097 | NONE | Patched | — | 2026-09-08 | Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved … |
| CVE-2026-77098 | NONE | Patched | — | 2026-09-08 | Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metric… |
| CVE-2026-86712 | HIGH | Patched | 8.8 | 2026-09-08 | SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled de… |
| CVE-2026-16502 | HIGH | 8.8 | 2026-09-08 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 via deserializati… | |
| CVE-2026-62650 | HIGH | 8.8 | 2026-09-08 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforce… | |
| CVE-2026-86439 | HIGH | Patched | 8.8 | 2026-09-07 | knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project di… |
| CVE-2026-86482 | HIGH | Patched | 8.8 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation |
| CVE-2026-86427 | HIGH | Patched | 8.8 | 2026-09-07 | LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to inject arbitrary rrdtool arguments b… |
| CVE-2026-86404 | HIGH | 8.8 | 2026-09-07 | EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list… | |
| CVE-2026-19633 | HIGH | Patched | 8.8 | 2026-09-06 | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that c… |
| CVE-2026-18480 | HIGH | Patched | 8.8 | 2026-09-06 | The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing use… |