Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 351–375 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-33389 HIGH 7.5 2026-09-08 An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices witho…
CVE-2026-33391 MEDIUM 5.4 2026-09-08 An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user wit…
CVE-2026-33465 MEDIUM Patched 6.5 2026-09-01 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with lo…
CVE-2026-33630 HIGH Patched 7.5 2026-09-03 c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's cal…
CVE-2026-33920 LOW 3.5 2026-09-08 A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token. An attacker …
CVE-2026-3416 MEDIUM 5.9 2026-09-03 The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks s…
CVE-2026-34223 HIGH 8.2 2026-09-08 A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desig…
CVE-2026-35160 MEDIUM 5.0 2026-09-03 Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerab…
CVE-2026-3850 MEDIUM 6.4 2026-09-02 The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb_contact_form` shortcode in all versions up to, and …
CVE-2026-3851 MEDIUM 6.4 2026-09-02 The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's legacy JSON format in all versions up to, and including, 4.27.6.…
CVE-2026-3852 MEDIUM 6.4 2026-09-03 The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `skype_url` shortcode attribute of the Social Media Follow module in all versions up to, a…
CVE-2026-3853 MEDIUM 6.4 2026-09-05 The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_pb_video_slider_item` shortcode in all versions…
CVE-2026-38961 NONE — 2026-09-04 Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated atta…
CVE-2026-4357 CRITICAL 10.0 2026-09-02 The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for un…
CVE-2026-4361 MEDIUM 5.0 2026-09-05 The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail…
CVE-2026-44402 CRITICAL 9.8 2026-09-04 Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to …
CVE-2026-44506 HIGH Patched 8.2 2026-09-03 Medplum is a developer platform that enables development of healthcare apps. In Medplum versions 4.1.10 through 5.1.6, the /oauth2/register endpoint could return the client…
CVE-2026-44756 CRITICAL 10.0 2026-09-08 A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a craf…
CVE-2026-44766 MEDIUM 6.5 2026-09-08 SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed b…
CVE-2026-45197 LOW 2.5 2026-09-04 Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a read and/or write data outside the Guest's virtualised G…
CVE-2026-45200 HIGH 7.8 2026-09-04 Software installed and run as a non-privileged user may conduct improper GPU driver IOCTL calls to create an allocation scenario that when freed would cause double free and…
CVE-2026-45221 HIGH Patched 7.8 2026-09-01 Konga before 2.1.0 contains a privilege escalation vulnerability that allows low-privileged local attackers to execute arbitrary code by planting attacker-controlled OpenSS…
CVE-2026-45730 HIGH Patched 8.3 2026-09-02 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0, there is a vulnerability in Nuclio Dashboard's project management API,…
CVE-2026-4644 NONE — 2026-09-04 A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated…
CVE-2026-46636 NONE Patched — 2026-09-04 Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instan…