Search
565 CVEs · published 2026-09-24 to 2026-09-24
CVEs (565, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 301–325 of 565 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-63493 | NONE | Patched | — | 2026-09-24 | Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with self.api permission can reach the personal-access-to… |
| CVE-2026-62368 | HIGH | Patched | 8.1 | 2026-09-24 | Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/A… |
| CVE-2026-56744 | NONE | Patched | — | 2026-09-24 | `@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@bsv/wallet-toolbox-mobile` provide client-focused dis… |
| CVE-2026-56738 | NONE | — | 2026-09-24 | phpMyFAQ is an open source FAQ web application. The `StopWords::add()` method inversions prior to 4.1.6 builds a SQL `INSERT` statement using `sprintf()` and inserts the us… | |
| CVE-2026-47132 | MEDIUM | 5.4 | 2026-09-24 | phpMyFAQ is an open source FAQ web application. Prior to version 4.2.0-alpha, an authenticated SQL LIKE wildcard injection vulnerability in phpMyFAQ’s chat user search allo… | |
| CVE-2026-26054 | NONE | Patched | — | 2026-09-24 | SumatraPDF is a multi-format reader for Windows. Prior to 3.6, the MobiDoc::ParseHeader function in src/MobiDoc.cpp validates a record using kMobiHeaderMinLen but DecodeMob… |
| CVE-2026-97226 | MEDIUM | 6.3 | 2026-09-24 | A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the file packages/api/src/controllers/files.js of the co… | |
| CVE-2026-97225 | MEDIUM | 6.3 | 2026-09-24 | A flaw has been found in DbGate up to 7.2.5-beta.5. This affects an unknown function of the file packages/api/src/controllers/runners.js of the component JSON Runner. Execu… | |
| CVE-2026-96873 | NONE | — | 2026-09-24 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - CirrusSearch extension allows Reflected XSS. This issue a… | |
| CVE-2026-96750 | HIGH | 7.1 | 2026-09-24 | MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view.… | |
| CVE-2026-96746 | MEDIUM | 6.5 | 2026-09-24 | An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the h… | |
| CVE-2026-96745 | MEDIUM | 5.6 | 2026-09-24 | Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driv… | |
| CVE-2026-96744 | HIGH | 7.1 | 2026-09-24 | Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supplied lock own… | |
| CVE-2026-93541 | MEDIUM | Patched | 6.5 | 2026-09-24 | An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a |
| CVE-2026-93425 | CRITICAL | Patched | 9.9 | 2026-09-24 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from… |
| CVE-2026-93283 | NONE | — | 2026-09-24 | In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix device_register() error path When device_register() fails in i3c_master_register_new_… | |
| CVE-2026-93282 | HIGH | 8.1 | 2026-09-24 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix maximum allowed access checks The DACL permission check looks for an ACE matching the curre… | |
| CVE-2026-93281 | NONE | — | 2026-09-24 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix HE extended capability length check rtw89_mac_check_he_obss_narrow_bw_ru_iter() reads… | |
| CVE-2026-93280 | HIGH | 8.8 | 2026-09-24 | In the Linux kernel, the following vulnerability has been resolved: greybus: audio: bound the topology section sizes against the fetched size gb_audio_gb_get_topology() f… | |
| CVE-2026-93279 | NONE | — | 2026-09-24 | In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown The TX cleanup tasklet can be schedul… | |
| CVE-2026-93278 | NONE | — | 2026-09-24 | In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown cvm_oct_rx_shutdown calls free_irq an… | |
| CVE-2026-93277 | HIGH | 7.8 | 2026-09-24 | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Validate udata before executing commands The destroy callbacks currently zero the udata … | |
| CVE-2026-93276 | NONE | — | 2026-09-24 | In the Linux kernel, the following vulnerability has been resolved: phy: renesas: phy-rcar-gen3-usb2: Fix devm action registration for disabled VBUS regulator devm_regula… | |
| CVE-2026-93275 | NONE | — | 2026-09-24 | In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/pt: Fix stop/start with no update If pt_event_stop() is called without PERF_EF_UPDATE f… | |
| CVE-2026-93274 | NONE | — | 2026-09-24 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: bcm2835: Don't remove an unregistered GPIO chip If the devm_pinctrl_register() function fails… |