Search
78,575 CVEs
CVEs (78,575, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 301–325 of 78,575 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-80133 | HIGH | 7.4 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthen… | |
| CVE-2026-80132 | HIGH | 8.1 | 2026-09-07 | ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulner… | |
| CVE-2026-79678 | HIGH | 8.1 | 2026-09-07 | A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDA… | |
| CVE-2026-76578 | CRITICAL | 9.8 | 2026-09-07 | A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. A… | |
| CVE-2026-6431 | HIGH | 7.2 | 2026-09-07 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Bi… | |
| CVE-2026-6223 | CRITICAL | 9.4 | 2026-09-07 | Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality BiHayat App allows Authentication Bypass. This issue affects BiHayat Ap… | |
| CVE-2026-61410 | CRITICAL | 9.4 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authorization vulnerability. An unauthenti… | |
| CVE-2026-61409 | HIGH | 7.3 | 2026-09-07 | Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command … | |
| CVE-2026-4945 | MEDIUM | 5.3 | 2026-09-07 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a… | |
| CVE-2026-12853 | MEDIUM | 5.4 | 2026-09-07 | The Flamingo plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2. This is due to the plugin not properly verifying that a… | |
| CVE-2022-51018 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not limit book page text length, page count, or author/title length. A player who obtains a writable book can create… |
| CVE-2022-51017 | HIGH | Patched | 7.5 | 2026-09-07 | PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 byte TAG_S… |
| CVE-2022-51016 | MEDIUM | Patched | 6.1 | 2026-09-07 | PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft Bedrock protocol encryption, so the server cannot verify that a connecting client possesses the private key c… |
| CVE-2022-51015 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP before 4.0.6 does not validate facing values in PlayerActionPacket (for START_BREAK and CRACK_BREAK actions) or in UseItemTransactionData (typically within In… |
| CVE-2022-51014 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP before 4.0.7 contains an unhandled exception vulnerability in the ModalFormResponsePacket handler when processing malformed JSON from clients. Attackers can s… |
| CVE-2022-51013 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data received from clients. Attackers can send negative or out-of-ran… |
| CVE-2022-51012 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafte… |
| CVE-2022-51011 | MEDIUM | Patched | 4.3 | 2026-09-07 | PocketMine-MP before 4.2.10 fails to validate the total length of incoming chat message blobs before splitting them by newline characters, allowing attackers to send large … |
| CVE-2022-51010 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP versions before 4.4.2 fail to properly validate item IDs received from clients in itemstack NBT data. Attackers can send crafted item IDs outside the valid ra… |
| CVE-2026-86404 | HIGH | 8.8 | 2026-09-07 | EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list… | |
| CVE-2026-86301 | LOW | 3.5 | 2026-09-07 | A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the compon… | |
| CVE-2026-86300 | HIGH | 7.3 | 2026-09-07 | A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the component Web Management. This manipulation causes improper authentic… | |
| CVE-2026-86299 | CRITICAL | 9.9 | 2026-09-07 | A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Ha… | |
| CVE-2026-78325 | NONE | — | 2026-09-07 | Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the… | |
| CVE-2026-2390 | MEDIUM | 6.4 | 2026-09-07 | The Powerkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lazy Load module's image processing in all versions up to, and including, 3.0.4. This… |