Search
140,640 CVEs · High severity
CVEs (140,640, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 326–350 of 140,640 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64197 | HIGH | Patched | 7.8 | 2026-09-03 | There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure.… |
| CVE-2026-64198 | HIGH | Patched | 7.8 | 2026-09-03 | There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a few bytes past the end of an allocated … |
| CVE-2026-64199 | HIGH | Patched | 7.8 | 2026-09-03 | There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read outside the bounds of an allocated data s… |
| CVE-2026-64200 | HIGH | Patched | 7.8 | 2026-09-03 | There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a past the end of an allocated heap buffe… |
| CVE-2026-64195 | HIGH | Patched | 7.8 | 2026-09-03 | There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-supplied data. Successful exploitation requires an attacker to get a user … |
| CVE-2026-64196 | HIGH | Patched | 7.8 | 2026-09-03 | There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heap. Successfu… |
| CVE-2026-8862 | HIGH | 7.5 | 2026-09-03 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container regis… | |
| CVE-2026-85208 | HIGH | 7.3 | 2026-09-03 | A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. The affected element is the function doInsert of the file /rider/orders/controller.… | |
| CVE-2026-82520 | HIGH | Patched | 7.5 | 2026-09-03 | parsedmarc before 11.0.1 decompresses gzip and ZIP attachments in a single unbounded read with no limit on decompressed output size. Because parsedmarc automatically proces… |
| CVE-2026-63376 | HIGH | Patched | 8.2 | 2026-09-03 | toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, al… |
| CVE-2026-77465 | HIGH | Patched | 7.5 | 2026-09-03 | toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0, toml.parse() uses a Peggy 5.1.0 generated recursive-descent parser in lib/parser.js whose peg$parsev… |
| CVE-2026-85053 | HIGH | 8.8 | 2026-09-03 | Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML… | |
| CVE-2026-85051 | HIGH | 8.8 | 2026-09-03 | Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chrom… | |
| CVE-2026-85048 | HIGH | 8.3 | 2026-09-03 | Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside t… | |
| CVE-2026-85049 | HIGH | 8.8 | 2026-09-03 | Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium sec… | |
| CVE-2026-85046 | HIGH | Patched | 8.8 | 2026-09-03 | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium secur… |
| CVE-2026-85045 | HIGH | 7.5 | 2026-09-03 | Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium secur… | |
| CVE-2026-82527 | HIGH | 7.5 | 2026-09-03 | R2R through 3.6.6 contains a SQL injection vulnerability that allows unauthenticated attackers to inject SQL predicates into the chunks search query by manipulating the fil… | |
| CVE-2026-44506 | HIGH | Patched | 8.2 | 2026-09-03 | Medplum is a developer platform that enables development of healthcare apps. In Medplum versions 4.1.10 through 5.1.6, the /oauth2/register endpoint could return the client… |
| CVE-2026-53728 | HIGH | Patched | 7.1 | 2026-09-03 | Medplum is a developer platform that enables development of healthcare apps. Prior to version 5.1.6, the external identity provider callback at GET /auth/external accepts a… |
| CVE-2026-85393 | HIGH | 7.5 | 2026-09-03 | node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage byte… | |
| CVE-2026-85395 | HIGH | Patched | 7.1 | 2026-09-03 | UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers wit… |
| CVE-2026-85396 | HIGH | Patched | 7.5 | 2026-09-03 | rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without … |
| CVE-2026-85028 | HIGH | Patched | 7.8 | 2026-09-03 | Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4… |
| CVE-2026-85388 | HIGH | 8.1 | 2026-09-03 | Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL… |