Search
13,088 CVEs
CVEs (13,088, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 251–275 of 13,088 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86195 | NONE | Patched | — | 2026-09-05 | grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested supe… |
| CVE-2026-86194 | NONE | Patched | — | 2026-09-05 | Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined on … |
| CVE-2026-86193 | NONE | Patched | — | 2026-09-05 | grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts… |
| CVE-2026-86192 | MEDIUM | 6.5 | 2026-09-05 | SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues… | |
| CVE-2026-86191 | MEDIUM | 4.3 | 2026-09-05 | SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attr… | |
| CVE-2026-86190 | CRITICAL | 9.1 | 2026-09-05 | WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and li… | |
| CVE-2026-8619 | HIGH | Patched | 7.5 | 2026-08-20 | An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of e… |
| CVE-2026-86189 | CRITICAL | 9.8 | 2026-09-05 | WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a cal… | |
| CVE-2026-86188 | HIGH | 7.2 | 2026-09-05 | AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browse… | |
| CVE-2026-86187 | MEDIUM | 5.9 | 2026-09-05 | WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to pass… | |
| CVE-2026-86186 | MEDIUM | 6.5 | 2026-09-05 | AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force p… | |
| CVE-2026-86185 | HIGH | 8.0 | 2026-09-05 | Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attack… | |
| CVE-2026-86184 | CRITICAL | Patched | 9.8 | 2026-09-05 | Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user … |
| CVE-2026-86183 | MEDIUM | 5.3 | 2026-09-06 | A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.… | |
| CVE-2026-86182 | MEDIUM | 4.3 | 2026-09-06 | A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.… | |
| CVE-2026-86181 | LOW | 3.5 | 2026-09-06 | A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the c… | |
| CVE-2026-86180 | HIGH | 7.3 | 2026-09-06 | A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the … | |
| CVE-2026-86179 | MEDIUM | 5.3 | 2026-09-06 | A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Ba… | |
| CVE-2026-86178 | MEDIUM | 5.4 | 2026-09-05 | Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only storie… | |
| CVE-2026-86177 | HIGH | Patched | 8.8 | 2026-09-05 | Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute … |
| CVE-2026-86176 | MEDIUM | 4.3 | 2026-09-05 | NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users wit… | |
| CVE-2026-86175 | MEDIUM | 6.5 | 2026-09-05 | NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve… | |
| CVE-2026-86174 | MEDIUM | 4.3 | 2026-09-05 | Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrar… | |
| CVE-2026-86173 | HIGH | 7.5 | 2026-09-05 | MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supp… | |
| CVE-2026-86172 | MEDIUM | 6.3 | 2026-09-06 | A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argum… |