Search
78,575 CVEs
CVEs (78,575, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 78,575 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85229 | NONE | Patched | — | 2026-09-04 | ** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI. This … |
| CVE-2026-80181 | NONE | Patched | — | 2026-09-04 | Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to … |
| CVE-2026-75754 | NONE | — | 2026-09-04 | Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obt… | |
| CVE-2026-67397 | NONE | — | 2026-09-04 | Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root. | |
| CVE-2026-67398 | NONE | Patched | — | 2026-09-04 | Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions fro… |
| CVE-2026-67402 | NONE | — | 2026-09-04 | An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated att… | |
| CVE-2026-18167 | NONE | — | 2026-09-03 | A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit crafted input that… | |
| CVE-2026-18330 | NONE | — | 2026-09-03 | A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may use the known shared … | |
| CVE-2026-85458 | NONE | — | 2026-09-03 | Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height. | |
| CVE-2026-85062 | NONE | Patched | — | 2026-09-03 | Colord is a tiny yet powerful tool for high-performance color manipulations and conversions. Prior to 2.9.4, synchronous CSS color string matchers in src/colorModels/rgbStr… |
| CVE-2026-85063 | NONE | Patched | — | 2026-09-03 | node-csv is a full-featured CSV parser with a simple API that is tested against large datasets. Prior to 7.0.2, csv-parse with the columns and group_columns_by_name options… |
| CVE-2026-15431 | NONE | — | 2026-09-03 | A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow… | |
| CVE-2026-85242 | NONE | — | 2026-09-03 | PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When only_global_lookup is enabled, the application va… | |
| CVE-2026-84736 | NONE | — | 2026-09-03 | In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for … | |
| CVE-2026-85236 | NONE | — | 2026-09-03 | A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while ac… | |
| CVE-2026-85237 | NONE | — | 2026-09-03 | A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The … | |
| CVE-2026-85238 | NONE | — | 2026-09-03 | MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth… | |
| CVE-2026-85239 | NONE | — | 2026-09-03 | A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template def… | |
| CVE-2026-75036 | NONE | Patched | — | 2026-09-03 | A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the m… |
| CVE-2026-57445 | NONE | — | 2026-09-03 | Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In … | |
| CVE-2026-53720 | NONE | Patched | — | 2026-09-03 | pymonocypher uses cython to wrap the Monocypher C library. Prior to version 4.0.2.8, the argon2i_32 implementation does not check the nb_blocks size. If the caller does not… |
| CVE-2026-53924 | NONE | Patched | — | 2026-09-03 | Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. Pri… |
| CVE-2026-85221 | NONE | — | 2026-09-03 | MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer property was not explicitly initialized and therefore defaulte… | |
| CVE-2026-85226 | NONE | — | 2026-09-03 | MISP contains an authorization flaw in the OnDemand correlation engine where correlations were calculated solely from matching attribute values without applying the distrib… | |
| CVE-2026-85227 | NONE | — | 2026-09-03 | MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in the event attribute filtering query builder. The taggedAttributes and galaxyAttachedAttributes URL par… |