Search
808 CVEs · Medium severity
CVEs (808, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 276–300 of 808 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-53760 | MEDIUM | 5.2 | 2026-09-04 | Admidio is an open-source user management solution. In versions 5.0.11 and prior, the modules/plugins.php endpoint handles plugin installation, uninstallation, and update o… | |
| CVE-2026-53756 | MEDIUM | Patched | 4.9 | 2026-09-04 | Emlog is an open source website building system. Prior to version 2.6.16, Emlog CMS Pro contains a blind SQL injection in User_Model::getUserDataByLogin(). The $account par… |
| CVE-2026-18149 | MEDIUM | Patched | 5.9 | 2026-09-04 | undici's retry handler can leave an already-exposed response body pending forever. When a server returns a successful response that declares a Content-Length, sends only pa… |
| CVE-2026-85024 | MEDIUM | Patched | 5.9 | 2026-09-04 | undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, whi… |
| CVE-2026-85014 | MEDIUM | Patched | 5.9 | 2026-09-04 | undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close handshake. On an uncle… |
| CVE-2026-84933 | MEDIUM | Patched | 6.5 | 2026-09-04 | undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache… |
| CVE-2026-18341 | MEDIUM | 6.3 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow. | |
| CVE-2026-18078 | MEDIUM | 4.3 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow. | |
| CVE-2026-18076 | MEDIUM | 4.3 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak. | |
| CVE-2026-18073 | MEDIUM | 4.4 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements. | |
| CVE-2026-17631 | MEDIUM | 5.0 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability. | |
| CVE-2026-17627 | MEDIUM | 4.9 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper … | |
| CVE-2026-17622 | MEDIUM | 6.5 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted d… | |
| CVE-2026-17621 | MEDIUM | 5.4 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing… | |
| CVE-2026-17499 | MEDIUM | 4.4 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| CVE-2026-17483 | MEDIUM | 4.3 | 2026-09-04 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure. | |
| CVE-2026-17470 | MEDIUM | 5.3 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow. | |
| CVE-2026-17469 | MEDIUM | 5.3 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser. | |
| CVE-2026-17444 | MEDIUM | 5.3 | 2026-09-04 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authen… | |
| CVE-2026-17443 | MEDIUM | 5.3 | 2026-09-04 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authen… | |
| CVE-2026-17442 | MEDIUM | 5.1 | 2026-09-04 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacke… | |
| CVE-2026-17440 | MEDIUM | 5.5 | 2026-09-04 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacke… | |
| CVE-2026-17274 | MEDIUM | 5.4 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds. | |
| CVE-2026-17273 | MEDIUM | 6.5 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference. | |
| CVE-2026-17270 | MEDIUM | 4.3 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow. |