Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

13,088 CVEs

CVEs (13,088, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 326–350 of 13,088 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-86060 NONE Patched — 2026-09-05 RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask …
CVE-2026-85787 MEDIUM Patched 6.5 2026-09-04 An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to …
CVE-2026-85786 HIGH Patched 7.5 2026-09-04 Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document…
CVE-2026-85781 HIGH Patched 8.7 2026-09-04 Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with…
CVE-2026-85769 MEDIUM 6.5 2026-09-04 A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migr…
CVE-2026-85730 NONE Patched — 2026-09-04 smol-toml is a small, fast, and correct TOML parser and serializer. Prior to 1.7.1, parse() can enter an infinite loop when a value inside an array or inline table is follo…
CVE-2026-85704 LOW 3.7 2026-09-04 A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file s…
CVE-2026-85703 MEDIUM 6.5 2026-09-04 A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/b…
CVE-2026-85702 HIGH 7.3 2026-09-04 A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file …
CVE-2026-85701 MEDIUM 5.3 2026-09-04 A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the fi…
CVE-2026-85700 MEDIUM 6.5 2026-09-04 Onyx 4.6.6 fails to properly restrict access to custom tool credentials stored in custom_headers, allowing any authenticated user to read admin-defined API keys. Attackers …
CVE-2026-85699 HIGH 7.5 2026-09-04 jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect …
CVE-2026-85698 MEDIUM 5.5 2026-09-04 Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attacker-controlled cell-count field without bounds valida…
CVE-2026-85697 MEDIUM 6.5 2026-09-04 Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can…
CVE-2026-85696 CRITICAL 9.8 2026-09-04 SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper esc…
CVE-2026-85695 CRITICAL 9.4 2026-09-04 FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and p…
CVE-2026-85694 HIGH 8.1 2026-09-04 LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from w…
CVE-2026-85693 MEDIUM 6.5 2026-09-04 Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other us…
CVE-2026-85692 MEDIUM 6.5 2026-09-04 Nightingale (n9e), as of commit 8362cbe (main branch, confirmed 2026-08-27), contains a server-side request forgery vulnerability in the isPublicIP function in aiagent/tool…
CVE-2026-85691 HIGH 7.5 2026-09-04 MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers…
CVE-2026-85690 HIGH 7.8 2026-09-04 Plandex 2.2.1 contains a path traversal vulnerability in the ApplyFiles function that allows attackers to write files outside the project directory. Attackers can influence…
CVE-2026-85689 MEDIUM 6.5 2026-09-04 llmware 0.4.6 contains an SQL injection vulnerability in the collection-database layer (llmware/resources.py) where filter and lookup values are directly string-interpolate…
CVE-2026-85688 CRITICAL 9.8 2026-09-04 TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and …
CVE-2026-85687 HIGH 7.5 2026-09-04 surya 0.22.1 screenshot server contains an unauthenticated arbitrary file read vulnerability in the /info, /page, and /process routes that accept raw file_path parameters. …
CVE-2026-85686 HIGH 7.5 2026-09-04 ms-swift 4.5.2 contains a server-side request forgery vulnerability in the swift deploy OpenAI-compatible API that fetches multimodal media URLs without validation or redir…