Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 276–300 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-85610 HIGH Patched 8.8 2026-09-04 OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering…
CVE-2026-85540 HIGH 8.8 2026-09-04 DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.
CVE-2026-85094 HIGH Patched 8.8 2026-09-04 The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebVie…
CVE-2026-85452 HIGH 8.8 2026-09-03 MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-by…
CVE-2026-85053 HIGH 8.8 2026-09-03 Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML…
CVE-2026-85051 HIGH 8.8 2026-09-03 Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chrom…
CVE-2026-85049 HIGH 8.8 2026-09-03 Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium sec…
CVE-2026-85046 HIGH Patched 8.8 2026-09-03 Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium secur…
CVE-2026-84752 HIGH 8.8 2026-09-03 Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.
CVE-2026-85236 NONE &mdash; 2026-09-03 A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while ac&hellip;
CVE-2026-71963 HIGH Patched 8.8 2026-09-03 Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supply&hellip;
CVE-2026-85199 NONE Patched &mdash; 2026-09-03 Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path traversal vulnerability in the REST API. User-controlled identifiers used to create, update, or dele&hellip;
CVE-2026-85176 HIGH 8.8 2026-09-03 DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers&hellip;
CVE-2026-85110 HIGH 8.8 2026-09-03 A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manip&hellip;
CVE-2026-85174 HIGH 8.8 2026-09-03 SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated att&hellip;
CVE-2026-85175 HIGH Patched 8.8 2026-09-03 SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.jso&hellip;
CVE-2026-80734 HIGH 8.8 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: btrfs: initialize inode mapping flags for cached inodes [BUG] When running generic/795 with 8K block s&hellip;
CVE-2026-78064 NONE &mdash; 2026-09-03 Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inherited FOF `save` task in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `fof.xml` grants the &hellip;
CVE-2026-53706 NONE Patched &mdash; 2026-09-02 PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the prevail eBPF verifier accepts ALU32 ADD and SUB instructio&hellip;
CVE-2026-20278 HIGH 8.8 2026-09-02 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security &hellip;
CVE-2026-20280 HIGH 8.8 2026-09-02 As part of Cisco's ongoing commitment to proactive security and product quality, the&nbsp;Cisco IOS XR Software engineering team has conducted a comprehensive internal secu&hellip;
CVE-2026-20275 HIGH 8.8 2026-09-02 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security &hellip;
CVE-2026-84668 HIGH 8.8 2026-09-02 Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replac&hellip;
CVE-2026-84669 HIGH 8.8 2026-09-02 A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permission on jobs that publish Allure report results to read arb&hellip;
CVE-2026-84670 HIGH 8.8 2026-09-02 Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in t&hellip;