Search
4,856 CVEs · High severity
CVEs (4,856, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 301–325 of 4,856 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-85455 | HIGH | 8.2 | 2026-09-03 | MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization… | |
| CVE-2026-85452 | HIGH | 8.8 | 2026-09-03 | MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-by… | |
| CVE-2026-85451 | HIGH | 7.1 | 2026-09-03 | MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command a… | |
| CVE-2026-85450 | HIGH | 7.5 | 2026-09-03 | MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers … | |
| CVE-2026-85449 | HIGH | 7.5 | 2026-09-03 | MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities from NODE_REPORT messages, allowing attackers to exhaust memory by supplying unbo… | |
| CVE-2026-85448 | HIGH | 7.5 | 2026-09-03 | MOOS-IvP uFldShoreBroker through 24.8.1 fails to limit the number of claimed communities stored in parallel vectors within ShoreBroker::handleMailNodePing(). A single publi… | |
| CVE-2026-85447 | HIGH | 7.5 | 2026-09-03 | MOOS-IvP pRealm through version 24.8.1 accepts unbounded REALMCAST_REQ subscriptions without validating duration or variable list limits. Attackers can register long-lived … | |
| CVE-2026-85446 | HIGH | 7.5 | 2026-09-03 | MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new node identity creates a ledger entry and triggers all-pairs di… | |
| CVE-2026-85445 | HIGH | 7.5 | 2026-09-03 | MOOS-IvP through 24.8.1 contains a denial of service vulnerability in the Demuxer::addMuxPacket() function that trusts the packet count declared in mux headers without vali… | |
| CVE-2026-85444 | HIGH | 7.5 | 2026-09-03 | MOOS-IvP through 24.8.1 contains a buffer over-read vulnerability in isQuoted(), isBraced(), and isChevroned() functions that strip whitespace but index using the original … | |
| CVE-2026-85443 | HIGH | 7.5 | 2026-09-03 | MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer::ListenLoop() where the accept thread performs a blocking receive without timeout… | |
| CVE-2026-85442 | HIGH | 7.5 | 2026-09-03 | MOOS core-moos through 10.4.0 fails to validate packet length declarations in CMOOSCommPkt::OnBytesWritten(), allowing unauthenticated attackers to trigger unbounded buffer… | |
| CVE-2026-85441 | HIGH | 7.5 | 2026-09-03 | MOOS core-moos through 10.4.0 fails to validate that serialized string lengths are non-negative in CMOOSMsg::operator>>. Unauthenticated attackers can send a crafted messag… | |
| CVE-2026-85439 | HIGH | 7.8 | 2026-09-03 | MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::handlePreCheckSplitDir() function that fails to sanitize shell metachara… | |
| CVE-2026-85436 | HIGH | 7.5 | 2026-09-03 | MOOS essential-moos through 10.0.1 contains a buffer overflow vulnerability in CMOOSUDPLink::ReadPktFromArray() that allows remote attackers to corrupt heap memory by sendi… | |
| CVE-2026-85432 | HIGH | 8.2 | 2026-09-03 | MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authenticated attackers to attribute writes to other clients by suppl… | |
| CVE-2026-85431 | HIGH | 7.5 | 2026-09-03 | MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP packet injection vulnerability in pMOOSBridge when configured with UDPListen. Attackers can send … | |
| CVE-2026-85429 | HIGH | 7.5 | 2026-09-03 | MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_M… | |
| CVE-2026-85427 | HIGH | 8.1 | 2026-09-03 | MOOS essential-moos pAntler through 10.0.1 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary programs by publishing … | |
| CVE-2026-85378 | HIGH | 7.3 | 2026-09-03 | A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function Au… | |
| CVE-2026-85225 | HIGH | 7.3 | 2026-09-03 | A vulnerability was identified in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient_login.php. The manipulation of t… | |
| CVE-2026-70178 | HIGH | 8.5 | 2026-09-03 | Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-69857 | HIGH | 8.5 | 2026-09-03 | Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network. | |
| CVE-2026-65818 | HIGH | 8.5 | 2026-09-03 | Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-62906 | HIGH | 7.4 | 2026-09-03 | Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network. |