Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 301–325 of 2,372 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85769 | MEDIUM | 6.5 | 2026-09-04 | A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migr… | |
| CVE-2026-85730 | NONE | Patched | — | 2026-09-04 | smol-toml is a small, fast, and correct TOML parser and serializer. Prior to 1.7.1, parse() can enter an infinite loop when a value inside an array or inline table is follo… |
| CVE-2026-85704 | LOW | 3.7 | 2026-09-04 | A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file s… | |
| CVE-2026-85703 | MEDIUM | 6.5 | 2026-09-04 | A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/b… | |
| CVE-2026-85702 | HIGH | 7.3 | 2026-09-04 | A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file … | |
| CVE-2026-85701 | MEDIUM | 5.3 | 2026-09-04 | A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the fi… | |
| CVE-2026-85700 | MEDIUM | 6.5 | 2026-09-04 | Onyx 4.6.6 fails to properly restrict access to custom tool credentials stored in custom_headers, allowing any authenticated user to read admin-defined API keys. Attackers … | |
| CVE-2026-85699 | HIGH | 7.5 | 2026-09-04 | jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect … | |
| CVE-2026-85698 | MEDIUM | 5.5 | 2026-09-04 | Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attacker-controlled cell-count field without bounds valida… | |
| CVE-2026-85697 | MEDIUM | 6.5 | 2026-09-04 | Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can… | |
| CVE-2026-85696 | CRITICAL | 9.8 | 2026-09-04 | SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper esc… | |
| CVE-2026-85695 | CRITICAL | 9.4 | 2026-09-04 | FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and p… | |
| CVE-2026-85694 | HIGH | 8.1 | 2026-09-04 | LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from w… | |
| CVE-2026-85693 | MEDIUM | 6.5 | 2026-09-04 | Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other us… | |
| CVE-2026-85692 | MEDIUM | 6.5 | 2026-09-04 | Nightingale (n9e), as of commit 8362cbe (main branch, confirmed 2026-08-27), contains a server-side request forgery vulnerability in the isPublicIP function in aiagent/tool… | |
| CVE-2026-85691 | HIGH | 7.5 | 2026-09-04 | MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers… | |
| CVE-2026-85690 | HIGH | 7.8 | 2026-09-04 | Plandex 2.2.1 contains a path traversal vulnerability in the ApplyFiles function that allows attackers to write files outside the project directory. Attackers can influence… | |
| CVE-2026-85689 | MEDIUM | 6.5 | 2026-09-04 | llmware 0.4.6 contains an SQL injection vulnerability in the collection-database layer (llmware/resources.py) where filter and lookup values are directly string-interpolate… | |
| CVE-2026-85688 | CRITICAL | 9.8 | 2026-09-04 | TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and … | |
| CVE-2026-85687 | HIGH | 7.5 | 2026-09-04 | surya 0.22.1 screenshot server contains an unauthenticated arbitrary file read vulnerability in the /info, /page, and /process routes that accept raw file_path parameters. … | |
| CVE-2026-85686 | HIGH | 7.5 | 2026-09-04 | ms-swift 4.5.2 contains a server-side request forgery vulnerability in the swift deploy OpenAI-compatible API that fetches multimodal media URLs without validation or redir… | |
| CVE-2026-85685 | HIGH | 7.5 | 2026-09-04 | AgentScope through 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill that copies arbitrary server directories into the agent workspace via an … | |
| CVE-2026-85684 | CRITICAL | 9.1 | 2026-09-04 | marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attac… | |
| CVE-2026-85676 | MEDIUM | 4.3 | 2026-09-04 | Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement. Attack… | |
| CVE-2026-85675 | HIGH | 7.5 | 2026-09-04 | OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no scheme, … |