Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

78,575 CVEs

CVEs (78,575, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 326–350 of 78,575 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-75166 NONE — 2026-09-04 Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows the low-privileged service user to execute /usr/bin/tcpdump as root without a pa…
CVE-2026-75167 NONE — 2026-09-04 A broken access control vulnerability in the ugw-usr-edit method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated use…
CVE-2022-35497 NONE — 2026-09-04 In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid session cookies via reflected cross-site scripting aff…
CVE-2026-82729 NONE Patched — 2026-09-04 Inefficient Algorithmic Complexity vulnerability in elixir-mint mint allows a remote HTTP server to exhaust CPU on the client host and cause a denial of service. parse_hex…
CVE-2026-82728 NONE Patched — 2026-09-04 Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client host and cause a denial o…
CVE-2026-52691 NONE — 2026-09-04 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module. …
CVE-2026-82309 NONE Patched — 2026-09-04 Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the name…
CVE-2026-85596 NONE Patched &mdash; 2026-09-04 Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS option generated for an Ingress carrying the ng&hellip;
CVE-2026-85597 NONE &mdash; 2026-09-04 Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate&hellip;
CVE-2026-85591 NONE Patched &mdash; 2026-09-04 phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account p&hellip;
CVE-2026-85594 NONE &mdash; 2026-09-04 Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kuberne&hellip;
CVE-2026-85595 NONE &mdash; 2026-09-04 Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames rec&hellip;
CVE-2026-85588 NONE Patched &mdash; 2026-09-04 phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP s&hellip;
CVE-2026-85589 NONE Patched &mdash; 2026-09-04 phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authenticati&hellip;
CVE-2026-85590 NONE Patched &mdash; 2026-09-04 phpMyFAQ before 4.1.8 contains an authentication bypass vulnerability in its two-factor authentication (TOTP) disable functionality. The removeTwofactorConfig() handler (re&hellip;
CVE-2026-85586 NONE Patched &mdash; 2026-09-04 phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTC&hellip;
CVE-2026-85587 NONE Patched &mdash; 2026-09-04 phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with onl&hellip;
CVE-2026-79707 NONE &mdash; 2026-09-04 A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote &hellip;
CVE-2026-4644 NONE &mdash; 2026-09-04 A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated&hellip;
CVE-2026-85546 NONE &mdash; 2026-09-04 MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions sh&hellip;
CVE-2026-85547 NONE &mdash; 2026-09-04 A cross-site request forgery (CSRF) vulnerability exists in MISP due to form-security and CSRF protections being disabled based on whether an incoming request was identifie&hellip;
CVE-2026-13148 NONE Patched &mdash; 2026-09-04 Missing release of memory after effective lifetime vulnerability in Softing smartLink allows resource leak exposure. This issue affects smartLink HW-PN: from 1.04 before 1.10.
CVE-2026-85533 NONE &mdash; 2026-09-04 An authorization flaw in MISP allowed an authenticated user to submit a sharing_group_id without verifying that the user was authorized to use the referenced Sharing Group.&hellip;
CVE-2026-85538 NONE &mdash; 2026-09-04 An incorrect authorization vulnerability in MISP allowed authenticated users to delete attributes from events despite lacking the required perm_modify or perm_modify_org pe&hellip;
CVE-2026-15937 NONE &mdash; 2026-09-04 Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID to reuse each other's mTLS certificate to authenticate against&hellip;