Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

13,088 CVEs

CVEs (13,088, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 301–325 of 13,088 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-86139 MEDIUM Patched 6.9 2026-09-05 In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
CVE-2026-86138 MEDIUM Patched 6.9 2026-09-05 In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
CVE-2026-86137 LOW Patched 2.9 2026-09-05 In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.
CVE-2026-86135 NONE — 2026-09-08 A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to trigger unauthorized snapshot cre…
CVE-2026-86124 CRITICAL 9.8 2026-09-05 AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. At…
CVE-2026-86123 HIGH 8.7 2026-09-05 SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified…
CVE-2026-86122 MEDIUM 5.0 2026-09-05 Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations. Attackers can point these URLs…
CVE-2026-86121 CRITICAL Patched 9.8 2026-09-05 Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthe…
CVE-2026-86120 MEDIUM 4.3 2026-09-05 APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission look…
CVE-2026-86119 HIGH 8.6 2026-09-05 Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGI…
CVE-2026-86118 MEDIUM Patched 4.3 2026-09-05 gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attacker…
CVE-2026-86117 HIGH 8.1 2026-09-05 Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address w…
CVE-2026-86116 MEDIUM Patched 6.5 2026-09-05 Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to create, modify, and delete glos…
CVE-2026-86115 MEDIUM Patched 5.0 2026-09-05 Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authenticati…
CVE-2026-86114 MEDIUM Patched 6.5 2026-09-05 Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including in…
CVE-2026-86113 MEDIUM 6.5 2026-09-05 BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to modify other users' reading record…
CVE-2026-86112 MEDIUM 5.4 2026-09-05 BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers to favorite or unfavorite follow…
CVE-2026-86111 MEDIUM 6.5 2026-09-05 BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message…
CVE-2026-86100 MEDIUM 6.4 2026-09-05 Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature. Authenticated attackers can sup…
CVE-2026-86098 HIGH Patched 7.4 2026-09-04 ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Att…
CVE-2026-86097 MEDIUM 6.5 2026-09-04 PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_backup_file() functions that allows attackers to cr…
CVE-2026-86096 MEDIUM 5.9 2026-09-04 PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race condition between task spawning and object deletion. A…
CVE-2026-86095 HIGH 7.8 2026-09-04 Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer withou…
CVE-2026-86091 HIGH Patched 7.1 2026-09-04 ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bin…
CVE-2026-86090 HIGH Patched 7.1 2026-09-04 ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST…