Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

163,528 CVEs · Medium severity

CVEs (163,528, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 251–275 of 163,528 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-86100 MEDIUM 6.4 2026-09-05 Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature. Authenticated attackers can sup…
CVE-2026-52774 MEDIUM Patched 6.1 2026-09-05 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki's Bazar widget handler reflects the id GET parameter into HTML attributes using strip_tags() only. …
CVE-2026-52773 MEDIUM Patched 6.1 2026-09-05 YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view reflects the time GET parameter into a hidden HTML inp…
CVE-2026-52772 MEDIUM Patched 5.5 2026-09-05 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field.label / field.hint in attribute and label-body…
CVE-2026-52763 MEDIUM Patched 6.5 2026-09-05 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the recentchanges action (actions/recentchanges.php) accepts a period argument from two disjoint parameter …
CVE-2026-86097 MEDIUM 6.5 2026-09-04 PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_backup_file() functions that allows attackers to cr…
CVE-2026-86096 MEDIUM 5.9 2026-09-04 PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race condition between task spawning and object deletion. A…
CVE-2026-76925 MEDIUM 5.8 2026-09-04 A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. This vulnerability occur…
CVE-2026-85787 MEDIUM Patched 6.5 2026-09-04 An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to …
CVE-2026-85703 MEDIUM 6.5 2026-09-04 A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/b…
CVE-2026-85701 MEDIUM 5.3 2026-09-04 A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the fi…
CVE-2026-77847 MEDIUM 6.5 2026-09-04 Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitiv…
CVE-2026-53769 MEDIUM Patched 6.5 2026-09-04 Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side up…
CVE-2026-85643 MEDIUM 4.7 2026-09-04 A flaw has been found in code-projects Online Shopping System 1.0. Impacted is the function mysqli_query of the file admin/adduser.php. Executing a manipulation of the argu…
CVE-2026-55513 MEDIUM Patched 5.4 2026-09-04 nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI host-creation path ignores both the…
CVE-2026-55512 MEDIUM Patched 5.3 2026-09-04 nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.2.0 to before version 0.5.0, when OIDC is enabled, GET /ui/oidc/login is reachable with…
CVE-2026-85639 MEDIUM 5.6 2026-09-04 A security vulnerability has been detected in jofpin trape 2.0. This vulnerability affects unknown code of the file core/user.py of the component Telemetry Endpoint. Such m…
CVE-2026-85637 MEDIUM 5.3 2026-09-04 A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affected by this issue is the function join_room of the file core/sockets.py of the component Admin Endpoint.…
CVE-2026-80115 MEDIUM Patched 6.1 2026-09-04 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation and denial-of-serv…
CVE-2026-85769 MEDIUM 6.5 2026-09-04 A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migr…
CVE-2026-85636 MEDIUM 5.3 2026-09-04 A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerability is an unknown functionality of the file core/stats.py of the component Login Endpoint. …
CVE-2026-84890 MEDIUM Patched 5.9 2026-09-04 undici's decompress interceptor decompresses response bodies according to the untrusted Content-Encoding header. While the number of content-encoding layers is capped, the …
CVE-2026-61688 MEDIUM 6.5 2026-09-04 SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API request history of any other user's API tokens within the …
CVE-2026-61614 MEDIUM 5.9 2026-09-04 SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tokens via a `?token=` URL query parameter as a fallbac…
CVE-2026-61608 MEDIUM 6.8 2026-09-04 SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, `UserInvitation` entities have no expiry timestamp. Invitation links mailed to users remain valid…