Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 2,372 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33389 | HIGH | 7.5 | 2026-09-08 | An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices witho… | |
| CVE-2026-33391 | MEDIUM | 5.4 | 2026-09-08 | An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user wit… | |
| CVE-2026-33465 | MEDIUM | Patched | 6.5 | 2026-09-01 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with lo… |
| CVE-2026-33630 | HIGH | Patched | 7.5 | 2026-09-03 | c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's cal… |
| CVE-2026-33920 | LOW | 3.5 | 2026-09-08 | A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token. An attacker … | |
| CVE-2026-3416 | MEDIUM | 5.9 | 2026-09-03 | The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks s… | |
| CVE-2026-34223 | HIGH | 8.2 | 2026-09-08 | A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desig… | |
| CVE-2026-35160 | MEDIUM | 5.0 | 2026-09-03 | Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerab… | |
| CVE-2026-3850 | MEDIUM | 6.4 | 2026-09-02 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb_contact_form` shortcode in all versions up to, and … | |
| CVE-2026-3851 | MEDIUM | 6.4 | 2026-09-02 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's legacy JSON format in all versions up to, and including, 4.27.6.… | |
| CVE-2026-3852 | MEDIUM | 6.4 | 2026-09-03 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `skype_url` shortcode attribute of the Social Media Follow module in all versions up to, a… | |
| CVE-2026-3853 | MEDIUM | 6.4 | 2026-09-05 | The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_pb_video_slider_item` shortcode in all versions… | |
| CVE-2026-38961 | NONE | — | 2026-09-04 | Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated atta… | |
| CVE-2026-4357 | CRITICAL | 10.0 | 2026-09-02 | The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for un… | |
| CVE-2026-4361 | MEDIUM | 5.0 | 2026-09-05 | The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail… | |
| CVE-2026-44402 | CRITICAL | 9.8 | 2026-09-04 | Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to … | |
| CVE-2026-44506 | HIGH | Patched | 8.2 | 2026-09-03 | Medplum is a developer platform that enables development of healthcare apps. In Medplum versions 4.1.10 through 5.1.6, the /oauth2/register endpoint could return the client… |
| CVE-2026-44756 | CRITICAL | 10.0 | 2026-09-08 | A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a craf… | |
| CVE-2026-44766 | MEDIUM | 6.5 | 2026-09-08 | SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed b… | |
| CVE-2026-45197 | LOW | 2.5 | 2026-09-04 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a read and/or write data outside the Guest's virtualised G… | |
| CVE-2026-45200 | HIGH | 7.8 | 2026-09-04 | Software installed and run as a non-privileged user may conduct improper GPU driver IOCTL calls to create an allocation scenario that when freed would cause double free and… | |
| CVE-2026-45221 | HIGH | Patched | 7.8 | 2026-09-01 | Konga before 2.1.0 contains a privilege escalation vulnerability that allows low-privileged local attackers to execute arbitrary code by planting attacker-controlled OpenSS… |
| CVE-2026-45730 | HIGH | Patched | 8.3 | 2026-09-02 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0, there is a vulnerability in Nuclio Dashboard's project management API,… |
| CVE-2026-4644 | NONE | — | 2026-09-04 | A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated… | |
| CVE-2026-46636 | NONE | Patched | — | 2026-09-04 | Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instan… |