Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

163,232 CVEs · Medium severity

EOL hidden · Show all products

CVEs (163,232, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 276–300 of 163,232 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-53760 MEDIUM 5.2 2026-09-04 Admidio is an open-source user management solution. In versions 5.0.11 and prior, the modules/plugins.php endpoint handles plugin installation, uninstallation, and update o…
CVE-2026-53756 MEDIUM Patched 4.9 2026-09-04 Emlog is an open source website building system. Prior to version 2.6.16, Emlog CMS Pro contains a blind SQL injection in User_Model::getUserDataByLogin(). The $account par…
CVE-2026-18149 MEDIUM Patched 5.9 2026-09-04 undici's retry handler can leave an already-exposed response body pending forever. When a server returns a successful response that declares a Content-Length, sends only pa…
CVE-2026-85024 MEDIUM Patched 5.9 2026-09-04 undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, whi…
CVE-2026-85014 MEDIUM Patched 5.9 2026-09-04 undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close handshake. On an uncle…
CVE-2026-84933 MEDIUM Patched 6.5 2026-09-04 undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache…
CVE-2026-18341 MEDIUM 6.3 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.
CVE-2026-18078 MEDIUM 4.3 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow.
CVE-2026-18076 MEDIUM 4.3 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak.
CVE-2026-18073 MEDIUM 4.4 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements.
CVE-2026-17631 MEDIUM 5.0 2026-09-04 IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.
CVE-2026-17627 MEDIUM 4.9 2026-09-04 IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper …
CVE-2026-17622 MEDIUM 6.5 2026-09-04 IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted d…
CVE-2026-17621 MEDIUM 5.4 2026-09-04 IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing…
CVE-2026-17499 MEDIUM 4.4 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVE-2026-17483 MEDIUM 4.3 2026-09-04 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure.
CVE-2026-17470 MEDIUM 5.3 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.
CVE-2026-17469 MEDIUM 5.3 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.
CVE-2026-17444 MEDIUM 5.3 2026-09-04 IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authen…
CVE-2026-17443 MEDIUM 5.3 2026-09-04 IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authen…
CVE-2026-17442 MEDIUM 5.1 2026-09-04 IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacke…
CVE-2026-17440 MEDIUM 5.5 2026-09-04 IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacke…
CVE-2026-17274 MEDIUM 5.4 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds.
CVE-2026-17273 MEDIUM 6.5 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference.
CVE-2026-17270 MEDIUM 4.3 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow.