Search
31,862 CVEs
CVEs (31,862, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 326–350 of 31,862 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0054 | NONE | — | 2026-09-08 | In isCallerAllowed of WalletContextualLocationsService.kt, there is a possible way to get wallet information due to a missing permission check. This could lead to local inf… | |
| CVE-2026-0065 | NONE | — | 2026-09-08 | In areBackgroundActivityStartsAllowed of BackgroundLaunchProcessController.java, there is a possible unintended way to launch activities in the background due to a logic er… | |
| CVE-2026-86074 | NONE | Patched | — | 2026-09-08 | n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow accepted a credential test or verification URL without… |
| CVE-2026-86073 | NONE | Patched | — | 2026-09-08 | n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endpoint bound an authorization code's first access token to the consented r… |
| CVE-2026-82514 | NONE | — | 2026-09-08 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-81531 | NONE | — | 2026-09-08 | An information disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization remains accessible after completion… | |
| CVE-2026-78997 | NONE | — | 2026-09-08 | UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary… | |
| CVE-2026-79570 | NONE | — | 2026-09-08 | mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to ac… | |
| CVE-2026-78216 | NONE | Patched | — | 2026-09-08 | AshLua exposes Ash read actions to Lua scripts run through an eval action. A read call accepts an operation (list, min, max, first, sum, avg) that builds an ad-hoc Ash.Quer… |
| CVE-2026-78230 | NONE | Patched | — | 2026-09-08 | AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, sum, avg) that builds an ad-hoc Ash.Query.Aggregate o… |
| CVE-2026-52307 | NONE | — | 2026-09-08 | An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management component of ClassCMS 1CMS v5.6 allows attackers to execute arbitrary web scripts … | |
| CVE-2026-86840 | NONE | — | 2026-09-08 | The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitra… | |
| CVE-2026-79573 | NONE | — | 2026-09-08 | L-ONE v1.0.0 was discovered to contain multiple SQL injection vulnerabilities in the /attachment/getBusinessUploadList component via the busid, id, and taskid parameters. T… | |
| CVE-2026-79574 | NONE | — | 2026-09-08 | An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message. | |
| CVE-2026-79572 | NONE | — | 2026-09-08 | An XXE (XML External Entity) vulnerability in the level-rule module of Distribution Management v1.0.0 allows attackers to read sensitive files, scan internal networks, or l… | |
| CVE-2026-16769 | NONE | — | 2026-09-08 | An unencrypted 'pause encryption request' message causes a denial of service in the in the RS9116W/SiWx917. See vulnerability B-E10 in the related paper below. | |
| CVE-2026-9034 | NONE | — | 2026-09-08 | Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a n… | |
| CVE-2026-9040 | NONE | — | 2026-09-08 | A race condition vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local no… | |
| CVE-2026-86135 | NONE | — | 2026-09-08 | A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to trigger unauthorized snapshot cre… | |
| CVE-2026-84282 | NONE | — | 2026-09-08 | A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint do… | |
| CVE-2026-79571 | NONE | — | 2026-09-08 | Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and… | |
| CVE-2026-79577 | NONE | — | 2026-09-08 | An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request. | |
| CVE-2026-7476 | NONE | — | 2026-09-08 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-… | |
| CVE-2026-7477 | NONE | — | 2026-09-08 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-… | |
| CVE-2026-78837 | NONE | — | 2026-09-08 | A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 allows attackers to access sensitive database information via a crafted SQL statement. |