Search
565 CVEs · published 2026-09-24 to 2026-09-24
CVEs (565, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 276–300 of 565 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-93284 | HIGH | 8.8 | 2026-09-24 | In the Linux kernel, the following vulnerability has been resolved: drm/pagemap: dma-unmap pages before handling migration errors drm_pagemap_migrate_unmap_pages() relies… | |
| CVE-2026-91161 | MEDIUM | Patched | 6.4 | 2026-09-24 | OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the GET /api/sessions/{sessionId}/groups/{groupId}/invite-code endpoint and the GroupGetIn… |
| CVE-2026-91160 | HIGH | Patched | 8.2 | 2026-09-24 | OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the /events WebSocket gateway delivers the session.qr event to a VIEWER API key that subsc… |
| CVE-2026-91134 | MEDIUM | Patched | 5.4 | 2026-09-24 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the Discourse post sanitizer allowed a stored cross-origin iframe to b… |
| CVE-2026-91133 | MEDIUM | Patched | 6.5 | 2026-09-24 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, authenticated users could supply unescaped SQL LIKE metacharacters to … |
| CVE-2026-91132 | MEDIUM | Patched | 4.3 | 2026-09-24 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, sites using wildcard patterns in the allowed_iframes setting could acc… |
| CVE-2026-91123 | HIGH | Patched | 7.2 | 2026-09-24 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the iframe src traversal guard did not treat literal backslashes as pa… |
| CVE-2026-91122 | HIGH | Patched | 8.7 | 2026-09-24 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the video placeholder component allowed crafted HTML to cause an attri… |
| CVE-2026-88390 | HIGH | 7.7 | 2026-09-24 | An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted JavaScript input containing an overlong token to trigger… | |
| CVE-2026-88385 | NONE | — | 2026-09-24 | Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data() during malformed XML parsing. Specially crafted XML input can cause text nodes allocated by mxmlNewT… | |
| CVE-2026-88384 | MEDIUM | 5.5 | 2026-09-24 | OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path. A specially crafted EXR file containing an unknown-type attribute with dataSize set to… | |
| CVE-2026-88383 | NONE | — | 2026-09-24 | libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind(). When parsing iCalendar data containing a parameterized property, the function pas… | |
| CVE-2026-88382 | HIGH | 7.5 | 2026-09-24 | hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggregate parser. | |
| CVE-2026-88378 | NONE | — | 2026-09-24 | QuickJS commit 04be24600 contains a heap out-of-bounds write condition in JS_ReadFunctionTag(). | |
| CVE-2026-88377 | NONE | — | 2026-09-24 | Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers. A specially crafted MP4 file containing an atom with a declared … | |
| CVE-2026-88376 | HIGH | 7.5 | 2026-09-24 | Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create(). A specially crafted MP4 file containing an avcC or hvcC ato… | |
| CVE-2026-88373 | NONE | — | 2026-09-24 | libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL() is called with a zero-length NAL unit, the resultin… | |
| CVE-2026-88372 | HIGH | 7.5 | 2026-09-24 | libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) files. | |
| CVE-2026-88367 | NONE | — | 2026-09-24 | NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasterization. A specially crafted SVG document containing a… | |
| CVE-2026-84302 | MEDIUM | Patched | 4.2 | 2026-09-24 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Discourse AI reviewables associated with private messages could appear… |
| CVE-2026-79766 | CRITICAL | Patched | 9.1 | 2026-09-24 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.1 until 2.5.1, an authenticated Termix administrator … |
| CVE-2026-79764 | HIGH | Patched | 7.7 | 2026-09-24 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0 until 2.5.1, the /homepage/proxy endpoint accepts a… |
| CVE-2026-79763 | MEDIUM | Patched | 5.3 | 2026-09-24 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.0 until 2.5.1, the POST /users/totp/disable and POST … |
| CVE-2026-79762 | MEDIUM | Patched | 5.5 | 2026-09-24 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0 until 2.5.1, Termix derives the keys that wrap OIDC… |
| CVE-2026-63498 | HIGH | Patched | 8.7 | 2026-09-24 | Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated us… |