Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 301–325 of 2,372 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84355 | LOW | Patched | 3.1 | 2026-09-02 | Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy… |
| CVE-2026-84359 | LOW | Patched | 3.1 | 2026-09-02 | Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted … |
| CVE-2026-84328 | LOW | Patched | 3.1 | 2026-09-02 | Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy v… |
| CVE-2026-84331 | LOW | Patched | 3.1 | 2026-09-02 | Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via … |
| CVE-2026-73745 | LOW | Patched | 3.1 | 2026-09-01 | A vulnerability in the API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some information handled by the affected system… |
| CVE-2026-73746 | LOW | Patched | 3.1 | 2026-09-01 | A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of ser… |
| CVE-2026-86505 | LOW | Patched | 3.3 | 2026-09-07 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace |
| CVE-2026-86503 | LOW | Patched | 3.3 | 2026-09-07 | In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching |
| CVE-2026-86485 | LOW | Patched | 3.3 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks |
| CVE-2026-86422 | LOW | Patched | 3.3 | 2026-09-07 | ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restricti… |
| CVE-2026-86423 | LOW | Patched | 3.3 | 2026-09-07 | ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick. A crafted call to the GetList metho… |
| CVE-2026-86425 | LOW | Patched | 3.3 | 2026-09-07 | ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted li… |
| CVE-2021-48006 | LOW | Patched | 3.3 | 2026-09-06 | PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but on… |
| CVE-2025-15614 | LOW | Patched | 3.3 | 2026-09-05 | ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files … |
| CVE-2026-18858 | LOW | 3.3 | 2026-09-04 | IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH. | |
| CVE-2023-3360 | LOW | Patched | 3.3 | 2026-09-02 | The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege use… |
| CVE-2026-81161 | LOW | 3.3 | 2026-09-02 | Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notificati… | |
| CVE-2026-86644 | LOW | 3.5 | 2026-09-08 | A vulnerability was determined in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_src/public/editor.md/editormd.js of the component API… | |
| CVE-2026-33920 | LOW | 3.5 | 2026-09-08 | A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token. An attacker … | |
| CVE-2026-76960 | LOW | 3.5 | 2026-09-08 | SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low pr… | |
| CVE-2026-76961 | LOW | 3.5 | 2026-09-08 | SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low pr… | |
| CVE-2026-86491 | LOW | Patched | 3.5 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads |
| CVE-2026-86301 | LOW | 3.5 | 2026-09-07 | A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the compon… | |
| CVE-2025-52652 | LOW | 3.5 | 2026-09-07 | HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content, making it appear as though it originates from a tru… | |
| CVE-2025-52657 | LOW | 3.5 | 2026-09-07 | HCL MyXalytics was affected by Potential DOS Vulnerability. It allows users to input data without any restriction on the number of characters which can impact system perfor… |