Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 326–350 of 2,372 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-75166 | NONE | — | 2026-09-04 | Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows the low-privileged service user to execute /usr/bin/tcpdump as root without a pa… | |
| CVE-2026-75167 | NONE | — | 2026-09-04 | A broken access control vulnerability in the ugw-usr-edit method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated use… | |
| CVE-2022-35497 | NONE | — | 2026-09-04 | In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid session cookies via reflected cross-site scripting aff… | |
| CVE-2026-82729 | NONE | Patched | — | 2026-09-04 | Inefficient Algorithmic Complexity vulnerability in elixir-mint mint allows a remote HTTP server to exhaust CPU on the client host and cause a denial of service. parse_hex… |
| CVE-2026-82728 | NONE | Patched | — | 2026-09-04 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client host and cause a denial o… |
| CVE-2026-52691 | NONE | — | 2026-09-04 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module. … | |
| CVE-2026-82309 | NONE | Patched | — | 2026-09-04 | Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the name… |
| CVE-2026-85596 | NONE | Patched | — | 2026-09-04 | Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS option generated for an Ingress carrying the ng… |
| CVE-2026-85597 | NONE | — | 2026-09-04 | Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate… | |
| CVE-2026-85591 | NONE | Patched | — | 2026-09-04 | phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account p… |
| CVE-2026-85594 | NONE | — | 2026-09-04 | Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kuberne… | |
| CVE-2026-85595 | NONE | — | 2026-09-04 | Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames rec… | |
| CVE-2026-85588 | NONE | Patched | — | 2026-09-04 | phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP s… |
| CVE-2026-85589 | NONE | Patched | — | 2026-09-04 | phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authenticati… |
| CVE-2026-85590 | NONE | Patched | — | 2026-09-04 | phpMyFAQ before 4.1.8 contains an authentication bypass vulnerability in its two-factor authentication (TOTP) disable functionality. The removeTwofactorConfig() handler (re… |
| CVE-2026-85586 | NONE | Patched | — | 2026-09-04 | phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTC… |
| CVE-2026-85587 | NONE | Patched | — | 2026-09-04 | phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with onl… |
| CVE-2026-79707 | NONE | — | 2026-09-04 | A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote … | |
| CVE-2026-4644 | NONE | — | 2026-09-04 | A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated… | |
| CVE-2026-85546 | NONE | — | 2026-09-04 | MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions sh… | |
| CVE-2026-85547 | NONE | — | 2026-09-04 | A cross-site request forgery (CSRF) vulnerability exists in MISP due to form-security and CSRF protections being disabled based on whether an incoming request was identifie… | |
| CVE-2026-13148 | NONE | Patched | — | 2026-09-04 | Missing release of memory after effective lifetime vulnerability in Softing smartLink allows resource leak exposure. This issue affects smartLink HW-PN: from 1.04 before 1.10. |
| CVE-2026-85533 | NONE | — | 2026-09-04 | An authorization flaw in MISP allowed an authenticated user to submit a sharing_group_id without verifying that the user was authorized to use the referenced Sharing Group.… | |
| CVE-2026-85538 | NONE | — | 2026-09-04 | An incorrect authorization vulnerability in MISP allowed authenticated users to delete attributes from events despite lacking the required perm_modify or perm_modify_org pe… | |
| CVE-2026-15937 | NONE | — | 2026-09-04 | Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID to reuse each other's mTLS certificate to authenticate against… |