Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

13,088 CVEs

CVEs (13,088, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 226–250 of 13,088 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-72581 HIGH 8.6 2026-08-10 A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to make the Xiaomi smart speaker perform HTTP reque…
CVE-2026-72582 HIGH 7.5 2026-08-10 A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to crash the server process with a single HTTP request. The…
CVE-2026-72583 MEDIUM 5.4 2026-08-10 A stored cross-site scripting (XSS) vulnerability in fastschema through v0.15.1 allows a low-privileged authenticated user to upload an SVG file containing malicious JavaSc…
CVE-2026-72584 HIGH 7.4 2026-08-10 A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an unauthenticated remote attacker to bypass the OTP attempt limit on the account r…
CVE-2026-72585 NONE — 2026-08-10 Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.
CVE-2026-72586 HIGH 7.5 2026-08-10 A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to query all historical sensor data via the DAQ_QUERY Sock…
CVE-2026-72587 MEDIUM 6.1 2026-08-10 A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to poison the shared process-wide render cache by manipulatin…
CVE-2026-72588 MEDIUM 5.3 2026-08-10 A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to determine whether a given email address is registered…
CVE-2026-72589 CRITICAL 9.8 2026-08-10 An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to execute arbitrary system commands by importing a…
CVE-2026-72590 CRITICAL 9.8 2026-08-10 An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to inject arbitrary cron job entries by sending a c…
CVE-2026-72591 HIGH 7.7 2026-08-10 A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make the server perform HTTP requests to arbitrary interna…
CVE-2026-72592 CRITICAL 9.8 2026-08-10 An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to execute arbitrary PHP code on the server. The applica…
CVE-2026-72593 CRITICAL 9.8 2026-08-10 A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to access the full file manager functionality including rea…
CVE-2026-72594 HIGH 7.6 2026-08-10 A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authenticated user to inject arbitrary JavaScript into the ap…
CVE-2026-59088 MEDIUM 5.5 2026-08-10 A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI image files. This occurs due to an incorrect calculati…
CVE-2026-64941 NONE Patched — 2026-08-10 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in phoenixframework phoenix_live_view allows an attacker to send a victim's browser to an origin of the at…
CVE-2026-68083 CRITICAL 9.1 2026-08-10 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix path resolution in ksmbd_vfs_kern_path_create The SMB2 open lookup is rooted at the share w…
CVE-2026-68084 NONE — 2026-08-10 In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: fix location monitor leak in tsi148 bridge tsi148_probe() allocates a location moni…
CVE-2026-68085 HIGH 8.0 2026-08-10 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled HCI_UART_SENDING bit in tx_sta…
CVE-2026-68086 NONE — 2026-08-10 In the Linux kernel, the following vulnerability has been resolved: mm/khugepaged: write all dirty file folios when collapsing [There is no upstream commit, as this code …
CVE-2026-68087 NONE — 2026-08-10 In the Linux kernel, the following vulnerability has been resolved: HID: wacom: use GFP_ATOMIC in wacom_wac_queue_flush() wacom_wac_queue_flush() is called via the .raw_e…
CVE-2026-68088 NONE — 2026-08-10 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: function: rndis: add length check to response query Add variable representations for BufL…
CVE-2026-68089 NONE — 2026-08-10 In the Linux kernel, the following vulnerability has been resolved: iio: core: fix uninitialized data in debugfs If *ppos is non-zero then simple_write_to_buffer() will n…
CVE-2026-68090 NONE — 2026-08-10 In the Linux kernel, the following vulnerability has been resolved: debugobjects: Plug race against a concurrent OOM disable syzbot reported a puzzling splat: WARNING…
CVE-2026-68091 HIGH 8.8 2026-08-10 In the Linux kernel, the following vulnerability has been resolved: HID: wacom: stop hardware after post-start probe failures wacom_parse_and_register() starts HID hardwa…