Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 251–275 of 2,372 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19302 | MEDIUM | 6.5 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links. | |
| CVE-2026-19303 | HIGH | 8.1 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to… | |
| CVE-2026-19304 | HIGH | 7.7 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy. | |
| CVE-2026-19305 | HIGH | 8.6 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery. | |
| CVE-2026-19306 | HIGH | 7.7 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JW… | |
| CVE-2026-19397 | NONE | — | 2026-09-08 | Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the… | |
| CVE-2026-19453 | HIGH | Patched | 7.1 | 2026-09-02 | The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting it admini… |
| CVE-2026-19471 | NONE | — | 2026-09-01 | Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, a… | |
| CVE-2026-19472 | NONE | — | 2026-09-01 | A denial-of-service security issue exists within ArmorStart® LT. The security issue stems from improper handling of a crafted HTTP PUT request sent to the embedded web serv… | |
| CVE-2026-19475 | MEDIUM | 6.5 | 2026-09-02 | An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafan… | |
| CVE-2026-19513 | HIGH | 8.1 | 2026-09-01 | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient validation of multi-f… | |
| CVE-2026-19534 | HIGH | Patched | 7.5 | 2026-09-04 | undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A defaul… |
| CVE-2026-19573 | HIGH | 7.2 | 2026-09-01 | The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doCommentShortcode’ function in all versions up to, and including, … | |
| CVE-2026-19590 | HIGH | 7.3 | 2026-09-01 | OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath settin… | |
| CVE-2026-19591 | HIGH | 8.8 | 2026-09-01 | OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser… | |
| CVE-2026-19592 | HIGH | 7.3 | 2026-09-01 | OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS automatically collected Git repository metadata without disabling the repository-loca… | |
| CVE-2026-19593 | CRITICAL | 9.8 | 2026-09-01 | OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a reposito… | |
| CVE-2026-19614 | NONE | — | 2026-09-08 | The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3. | |
| CVE-2026-19633 | HIGH | Patched | 8.8 | 2026-09-06 | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that c… |
| CVE-2026-19634 | MEDIUM | Patched | 6.4 | 2026-09-06 | PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names.… |
| CVE-2026-19645 | MEDIUM | 6.5 | 2026-09-04 | IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cau… | |
| CVE-2026-19649 | MEDIUM | 6.2 | 2026-09-04 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacke… | |
| CVE-2026-19698 | LOW | Patched | 3.5 | 2026-09-02 | The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using them to build the CSS it outputs on the front end, a… |
| CVE-2026-19704 | MEDIUM | Patched | 5.3 | 2026-09-02 | The Comments WordPress plugin before 7.6.66 does not validate a value used to build a database query, allowing unauthenticated users to inject SQL and read comments they a… |
| CVE-2026-19719 | MEDIUM | Patched | 6.8 | 2026-09-02 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline JavaScript event handle… |