Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 351–375 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-79684 HIGH 8.8 2026-09-01 Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass …
CVE-2026-58571 HIGH 8.8 2026-09-01 Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitr…
CVE-2026-58572 HIGH 8.8 2026-09-01 Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary cod…
CVE-2026-84131 HIGH Patched 8.8 2026-09-01 Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.…
CVE-2026-84123 HIGH Patched 8.8 2026-09-01 Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbi…
CVE-2026-84128 HIGH Patched 8.8 2026-09-01 Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
CVE-2026-84117 HIGH Patched 8.8 2026-09-01 Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.
CVE-2026-79683 HIGH 8.8 2026-09-01 Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write a…
CVE-2026-58575 HIGH 8.8 2026-09-01 Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges t…
CVE-2026-76111 HIGH 8.8 2026-09-01 Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke admi…
CVE-2026-59681 HIGH 8.8 2026-09-01 A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory configuration values to execute arbitrary commands as root on the…
CVE-2026-19806 HIGH 8.8 2026-09-01 The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administ…
CVE-2026-65643 HIGH Patched 8.8 2026-09-01 Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
CVE-2026-33197 NONE — 2026-09-08 AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access. Successful exploitation of this vu…
CVE-2026-77103 NONE Patched — 2026-09-08 CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Up…
CVE-2026-77105 NONE Patched — 2026-09-08 CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServ…
CVE-2026-77101 NONE Patched — 2026-09-08 CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
CVE-2026-77102 NONE Patched — 2026-09-08 CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
CVE-2026-12611 NONE — 2026-09-08 A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole ser…
CVE-2026-80219 HIGH 8.7 2026-09-08 A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient with automatic grant approval (GrantMethod: au…
CVE-2026-86452 NONE — 2026-09-07 Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/…
CVE-2026-19204 NONE — 2026-09-07 A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exha…
CVE-2026-84732 NONE — 2026-09-07 Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a t…
CVE-2026-14297 NONE — 2026-09-07 A buffer overflow in the Bluetooth Continuous Glucose Monitoring Service (CGMS) Record Access Control Point (RACP) write handler allows an authenticated BLE peer …
CVE-2026-67281 NONE Patched — 2026-09-05 RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer use…