Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 2,372 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85592 | LOW | Patched | 3.7 | 2026-09-04 | phpMyFAQ before 4.1.8 contains an authorization bypass vulnerability in the question creation endpoint where the isAddingQuestionsAllowed() method grants access to all call… |
| CVE-2026-84969 | LOW | 3.7 | 2026-09-03 | A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field i… | |
| CVE-2026-85030 | LOW | 3.7 | 2026-09-03 | A vulnerability has been found in HKUDS AI-Trader up to d03ff6c056b32ced735adf7c19ed8175adb1c8df. The affected element is an unknown function of the file service/server/rou… | |
| CVE-2026-81168 | LOW | 3.7 | 2026-09-02 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Pa… | |
| CVE-2026-81159 | LOW | 3.7 | 2026-09-02 | Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0. | |
| CVE-2026-77783 | LOW | Patched | 3.7 | 2026-09-02 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front end is publicly viewable, allowing unauthenticated vis… |
| CVE-2026-84367 | LOW | Patched | 3.7 | 2026-09-01 | joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.5 and 18.2.4, joi's lib/types/keys.js internals.rename() implementation used… |
| CVE-2026-84368 | LOW | Patched | 3.7 | 2026-09-01 | joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.6 and 18.2.5, the @hapi/joi package through 17.1.1 and the successor joi pac… |
| CVE-2026-84307 | LOW | Patched | 3.7 | 2026-09-01 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.5 and 5.7.5, packages/panels/src/Auth/Pages/Login.php presents … |
| CVE-2026-73743 | LOW | Patched | 3.7 | 2026-09-01 | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to gain insight into some data handle… |
| CVE-2023-54356 | LOW | Patched | 3.7 | 2026-09-01 | Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These… |
| CVE-2026-48932 | LOW | 3.7 | 2026-09-01 | A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` he… | |
| CVE-2026-73318 | LOW | Patched | 3.8 | 2026-09-08 | XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP administrator to access and submit force-agreemen… |
| CVE-2026-14326 | LOW | 3.8 | 2026-09-02 | The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff rol… | |
| CVE-2026-81198 | LOW | Patched | 3.8 | 2026-09-02 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated u… |
| CVE-2026-86150 | MEDIUM | 4.1 | 2026-09-05 | A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument … | |
| CVE-2026-83543 | MEDIUM | Patched | 4.1 | 2026-09-05 | The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above … |
| CVE-2026-82186 | MEDIUM | Patched | 4.1 | 2026-09-04 | The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it in a SQL query, allowing users with administrator p… |
| CVE-2026-74768 | MEDIUM | 4.1 | 2026-09-03 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability in the REST API. A high privileged remote attacker c… | |
| CVE-2026-16647 | MEDIUM | Patched | 4.1 | 2026-09-02 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versi… |
| CVE-2026-82182 | MEDIUM | Patched | 4.1 | 2026-09-02 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied list of identifiers before using it in a SQL query, allowing adm… |
| CVE-2026-84962 | MEDIUM | 4.2 | 2026-09-03 | An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's iden… | |
| CVE-2026-84657 | MEDIUM | 4.2 | 2026-09-02 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to… | |
| CVE-2026-84358 | MEDIUM | Patched | 4.2 | 2026-09-02 | Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar v… |
| CVE-2026-78606 | MEDIUM | Patched | 4.2 | 2026-09-01 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by … |