Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

140,640 CVEs · High severity

CVEs (140,640, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 326–350 of 140,640 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-64200 HIGH Patched 7.8 2026-09-03 There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a past the end of an allocated heap buffe…
CVE-2026-64199 HIGH Patched 7.8 2026-09-03 There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read outside the bounds of an allocated data s…
CVE-2026-64198 HIGH Patched 7.8 2026-09-03 There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a few bytes past the end of an allocated …
CVE-2026-64197 HIGH Patched 7.8 2026-09-03 There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure.…
CVE-2026-64196 HIGH Patched 7.8 2026-09-03 There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heap. Successfu…
CVE-2026-64195 HIGH Patched 7.8 2026-09-03 There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-supplied data. Successful exploitation requires an attacker to get a user …
CVE-2026-8862 HIGH 7.5 2026-09-03 IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container regis…
CVE-2026-85208 HIGH 7.3 2026-09-03 A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. The affected element is the function doInsert of the file /rider/orders/controller.…
CVE-2026-82520 HIGH Patched 7.5 2026-09-03 parsedmarc before 11.0.1 decompresses gzip and ZIP attachments in a single unbounded read with no limit on decompressed output size. Because parsedmarc automatically proces…
CVE-2026-77465 HIGH Patched 7.5 2026-09-03 toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0, toml.parse() uses a Peggy 5.1.0 generated recursive-descent parser in lib/parser.js whose peg$parsev…
CVE-2026-63376 HIGH Patched 8.2 2026-09-03 toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, al…
CVE-2026-85053 HIGH 8.8 2026-09-03 Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML…
CVE-2026-85051 HIGH 8.8 2026-09-03 Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chrom…
CVE-2026-85049 HIGH 8.8 2026-09-03 Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium sec…
CVE-2026-85048 HIGH 8.3 2026-09-03 Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside t…
CVE-2026-85046 HIGH Patched 8.8 2026-09-03 Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium secur…
CVE-2026-85045 HIGH 7.5 2026-09-03 Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium secur…
CVE-2026-82527 HIGH 7.5 2026-09-03 R2R through 3.6.6 contains a SQL injection vulnerability that allows unauthenticated attackers to inject SQL predicates into the chunks search query by manipulating the fil…
CVE-2026-53728 HIGH Patched 7.1 2026-09-03 Medplum is a developer platform that enables development of healthcare apps. Prior to version 5.1.6, the external identity provider callback at GET /auth/external accepts a…
CVE-2026-44506 HIGH Patched 8.2 2026-09-03 Medplum is a developer platform that enables development of healthcare apps. In Medplum versions 4.1.10 through 5.1.6, the /oauth2/register endpoint could return the client…
CVE-2026-85396 HIGH Patched 7.5 2026-09-03 rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without …
CVE-2026-85395 HIGH Patched 7.1 2026-09-03 UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers wit…
CVE-2026-85393 HIGH 7.5 2026-09-03 node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage byte…
CVE-2026-85390 HIGH 7.1 2026-09-03 Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform admin…
CVE-2026-85388 HIGH 8.1 2026-09-03 Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL…