Search
13,088 CVEs
CVEs (13,088, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 326–350 of 13,088 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86060 | NONE | Patched | — | 2026-09-05 | RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask … |
| CVE-2026-85787 | MEDIUM | Patched | 6.5 | 2026-09-04 | An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to … |
| CVE-2026-85786 | HIGH | Patched | 7.5 | 2026-09-04 | Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document… |
| CVE-2026-85781 | HIGH | Patched | 8.7 | 2026-09-04 | Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with… |
| CVE-2026-85769 | MEDIUM | 6.5 | 2026-09-04 | A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migr… | |
| CVE-2026-85730 | NONE | Patched | — | 2026-09-04 | smol-toml is a small, fast, and correct TOML parser and serializer. Prior to 1.7.1, parse() can enter an infinite loop when a value inside an array or inline table is follo… |
| CVE-2026-85704 | LOW | 3.7 | 2026-09-04 | A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file s… | |
| CVE-2026-85703 | MEDIUM | 6.5 | 2026-09-04 | A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/b… | |
| CVE-2026-85702 | HIGH | 7.3 | 2026-09-04 | A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file … | |
| CVE-2026-85701 | MEDIUM | 5.3 | 2026-09-04 | A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the fi… | |
| CVE-2026-85700 | MEDIUM | 6.5 | 2026-09-04 | Onyx 4.6.6 fails to properly restrict access to custom tool credentials stored in custom_headers, allowing any authenticated user to read admin-defined API keys. Attackers … | |
| CVE-2026-85699 | HIGH | 7.5 | 2026-09-04 | jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect … | |
| CVE-2026-85698 | MEDIUM | 5.5 | 2026-09-04 | Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attacker-controlled cell-count field without bounds valida… | |
| CVE-2026-85697 | MEDIUM | 6.5 | 2026-09-04 | Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can… | |
| CVE-2026-85696 | CRITICAL | 9.8 | 2026-09-04 | SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper esc… | |
| CVE-2026-85695 | CRITICAL | 9.4 | 2026-09-04 | FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and p… | |
| CVE-2026-85694 | HIGH | 8.1 | 2026-09-04 | LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from w… | |
| CVE-2026-85693 | MEDIUM | 6.5 | 2026-09-04 | Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other us… | |
| CVE-2026-85692 | MEDIUM | 6.5 | 2026-09-04 | Nightingale (n9e), as of commit 8362cbe (main branch, confirmed 2026-08-27), contains a server-side request forgery vulnerability in the isPublicIP function in aiagent/tool… | |
| CVE-2026-85691 | HIGH | 7.5 | 2026-09-04 | MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers… | |
| CVE-2026-85690 | HIGH | 7.8 | 2026-09-04 | Plandex 2.2.1 contains a path traversal vulnerability in the ApplyFiles function that allows attackers to write files outside the project directory. Attackers can influence… | |
| CVE-2026-85689 | MEDIUM | 6.5 | 2026-09-04 | llmware 0.4.6 contains an SQL injection vulnerability in the collection-database layer (llmware/resources.py) where filter and lookup values are directly string-interpolate… | |
| CVE-2026-85688 | CRITICAL | 9.8 | 2026-09-04 | TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and … | |
| CVE-2026-85687 | HIGH | 7.5 | 2026-09-04 | surya 0.22.1 screenshot server contains an unauthenticated arbitrary file read vulnerability in the /info, /page, and /process routes that accept raw file_path parameters. … | |
| CVE-2026-85686 | HIGH | 7.5 | 2026-09-04 | ms-swift 4.5.2 contains a server-side request forgery vulnerability in the swift deploy OpenAI-compatible API that fetches multimodal media URLs without validation or redir… |