Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

565 CVEs · published 2026-09-24 to 2026-09-24

CVEs (565, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 301–325 of 565 (capped at 500)

CVE ID Severity Patch CVSS Published ↓ Description
CVE-2026-63493 NONE Patched — 2026-09-24 Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with self.api permission can reach the personal-access-to…
CVE-2026-62368 HIGH Patched 8.1 2026-09-24 Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/A…
CVE-2026-56744 NONE Patched — 2026-09-24 `@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@bsv/wallet-toolbox-mobile` provide client-focused dis…
CVE-2026-56738 NONE — 2026-09-24 phpMyFAQ is an open source FAQ web application. The `StopWords::add()` method inversions prior to 4.1.6 builds a SQL `INSERT` statement using `sprintf()` and inserts the us…
CVE-2026-47132 MEDIUM 5.4 2026-09-24 phpMyFAQ is an open source FAQ web application. Prior to version 4.2.0-alpha, an authenticated SQL LIKE wildcard injection vulnerability in phpMyFAQ’s chat user search allo…
CVE-2026-26054 NONE Patched — 2026-09-24 SumatraPDF is a multi-format reader for Windows. Prior to 3.6, the MobiDoc::ParseHeader function in src/MobiDoc.cpp validates a record using kMobiHeaderMinLen but DecodeMob…
CVE-2026-97226 MEDIUM 6.3 2026-09-24 A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the file packages/api/src/controllers/files.js of the co…
CVE-2026-97225 MEDIUM 6.3 2026-09-24 A flaw has been found in DbGate up to 7.2.5-beta.5. This affects an unknown function of the file packages/api/src/controllers/runners.js of the component JSON Runner. Execu…
CVE-2026-96873 NONE — 2026-09-24 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - CirrusSearch extension allows Reflected XSS. This issue a…
CVE-2026-96750 HIGH 7.1 2026-09-24 MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view.…
CVE-2026-96746 MEDIUM 6.5 2026-09-24 An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the h…
CVE-2026-96745 MEDIUM 5.6 2026-09-24 Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driv…
CVE-2026-96744 HIGH 7.1 2026-09-24 Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supplied lock own…
CVE-2026-93541 MEDIUM Patched 6.5 2026-09-24 An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a
CVE-2026-93425 CRITICAL Patched 9.9 2026-09-24 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from…
CVE-2026-93283 NONE — 2026-09-24 In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix device_register() error path When device_register() fails in i3c_master_register_new_…
CVE-2026-93282 HIGH 8.1 2026-09-24 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix maximum allowed access checks The DACL permission check looks for an ACE matching the curre…
CVE-2026-93281 NONE — 2026-09-24 In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix HE extended capability length check rtw89_mac_check_he_obss_narrow_bw_ru_iter() reads…
CVE-2026-93280 HIGH 8.8 2026-09-24 In the Linux kernel, the following vulnerability has been resolved: greybus: audio: bound the topology section sizes against the fetched size gb_audio_gb_get_topology() f…
CVE-2026-93279 NONE — 2026-09-24 In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown The TX cleanup tasklet can be schedul…
CVE-2026-93278 NONE — 2026-09-24 In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown cvm_oct_rx_shutdown calls free_irq an…
CVE-2026-93277 HIGH 7.8 2026-09-24 In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Validate udata before executing commands The destroy callbacks currently zero the udata …
CVE-2026-93276 NONE — 2026-09-24 In the Linux kernel, the following vulnerability has been resolved: phy: renesas: phy-rcar-gen3-usb2: Fix devm action registration for disabled VBUS regulator devm_regula…
CVE-2026-93275 NONE — 2026-09-24 In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/pt: Fix stop/start with no update If pt_event_stop() is called without PERF_EF_UPDATE f…
CVE-2026-93274 NONE — 2026-09-24 In the Linux kernel, the following vulnerability has been resolved: pinctrl: bcm2835: Don't remove an unregistered GPIO chip If the devm_pinctrl_register() function fails…