Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 2,372 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-79684 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass … | |
| CVE-2026-58571 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitr… | |
| CVE-2026-58572 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary cod… | |
| CVE-2026-84131 | HIGH | Patched | 8.8 | 2026-09-01 | Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.… |
| CVE-2026-84123 | HIGH | Patched | 8.8 | 2026-09-01 | Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbi… |
| CVE-2026-84128 | HIGH | Patched | 8.8 | 2026-09-01 | Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155. |
| CVE-2026-84117 | HIGH | Patched | 8.8 | 2026-09-01 | Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155. |
| CVE-2026-79683 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write a… | |
| CVE-2026-58575 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges t… | |
| CVE-2026-76111 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke admi… | |
| CVE-2026-59681 | HIGH | 8.8 | 2026-09-01 | A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory configuration values to execute arbitrary commands as root on the… | |
| CVE-2026-19806 | HIGH | 8.8 | 2026-09-01 | The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administ… | |
| CVE-2026-65643 | HIGH | Patched | 8.8 | 2026-09-01 | Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root. |
| CVE-2026-33197 | NONE | — | 2026-09-08 | AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access. Successful exploitation of this vu… | |
| CVE-2026-77103 | NONE | Patched | — | 2026-09-08 | CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Up… |
| CVE-2026-77105 | NONE | Patched | — | 2026-09-08 | CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServ… |
| CVE-2026-77101 | NONE | Patched | — | 2026-09-08 | CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe. |
| CVE-2026-77102 | NONE | Patched | — | 2026-09-08 | CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe. |
| CVE-2026-12611 | NONE | — | 2026-09-08 | A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole ser… | |
| CVE-2026-80219 | HIGH | 8.7 | 2026-09-08 | A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient with automatic grant approval (GrantMethod: au… | |
| CVE-2026-86452 | NONE | — | 2026-09-07 | Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/… | |
| CVE-2026-19204 | NONE | — | 2026-09-07 | A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exha… | |
| CVE-2026-84732 | NONE | — | 2026-09-07 | Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a t… | |
| CVE-2026-14297 | NONE | — | 2026-09-07 | A buffer overflow in the Bluetooth Continuous Glucose Monitoring Service (CGMS) Record Access Control Point (RACP) write handler allows an authenticated BLE peer … | |
| CVE-2026-67281 | NONE | Patched | — | 2026-09-05 | RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer use… |