Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 351–375 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-85229 NONE Patched — 2026-09-04 ** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI. This …
CVE-2026-80181 NONE Patched — 2026-09-04 Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to …
CVE-2026-75754 NONE — 2026-09-04 Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obt…
CVE-2026-67397 NONE — 2026-09-04 Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.
CVE-2026-67398 NONE Patched — 2026-09-04 Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions fro…
CVE-2026-67402 NONE — 2026-09-04 An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated att…
CVE-2026-18167 NONE — 2026-09-03 A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit crafted input that…
CVE-2026-18330 NONE — 2026-09-03 A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may use the known shared …
CVE-2026-85458 NONE — 2026-09-03 Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height.
CVE-2026-85062 NONE Patched — 2026-09-03 Colord is a tiny yet powerful tool for high-performance color manipulations and conversions. Prior to 2.9.4, synchronous CSS color string matchers in src/colorModels/rgbStr…
CVE-2026-85063 NONE Patched — 2026-09-03 node-csv is a full-featured CSV parser with a simple API that is tested against large datasets. Prior to 7.0.2, csv-parse with the columns and group_columns_by_name options…
CVE-2026-15431 NONE — 2026-09-03 A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow…
CVE-2026-85242 NONE — 2026-09-03 PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When only_global_lookup is enabled, the application va…
CVE-2026-84736 NONE — 2026-09-03 In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for …
CVE-2026-85236 NONE — 2026-09-03 A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while ac…
CVE-2026-85237 NONE — 2026-09-03 A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The …
CVE-2026-85238 NONE — 2026-09-03 MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth…
CVE-2026-85239 NONE — 2026-09-03 A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template def…
CVE-2026-75036 NONE Patched — 2026-09-03 A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the m…
CVE-2026-57445 NONE — 2026-09-03 Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In …
CVE-2026-53720 NONE Patched — 2026-09-03 pymonocypher uses cython to wrap the Monocypher C library. Prior to version 4.0.2.8, the argon2i_32 implementation does not check the nb_blocks size. If the caller does not…
CVE-2026-53924 NONE Patched — 2026-09-03 Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. Pri…
CVE-2026-85221 NONE — 2026-09-03 MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer property was not explicitly initialized and therefore defaulte…
CVE-2026-85226 NONE — 2026-09-03 MISP contains an authorization flaw in the OnDemand correlation engine where correlations were calculated solely from matching attribute values without applying the distrib…
CVE-2026-85227 NONE — 2026-09-03 MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in the event attribute filtering query builder. The taggedAttributes and galaxyAttachedAttributes URL par…