Search
31,862 CVEs
CVEs (31,862, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 31,862 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5729 | NONE | — | 2026-09-08 | Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform … | |
| CVE-2026-70613 | NONE | — | 2026-09-08 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-70614 | NONE | — | 2026-09-08 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-33197 | NONE | — | 2026-09-08 | AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access. Successful exploitation of this vu… | |
| CVE-2026-11891 | NONE | — | 2026-09-08 | Use After Free vulnerability in Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform … | |
| CVE-2026-12285 | NONE | — | 2026-09-08 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-… | |
| CVE-2026-12387 | NONE | — | 2026-09-08 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-… | |
| CVE-2026-0860 | NONE | — | 2026-09-08 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a l… | |
| CVE-2026-78838 | NONE | — | 2026-09-08 | A reflected cross-site scripting (XSS) vulnerability in the grid_datasource.php component of AppNitro MachForm v30 allows attackers to execute arbitrary Javascript in the c… | |
| CVE-2026-79379 | NONE | Patched | — | 2026-09-08 | A buffer overflow in the SBC_DecodeFrames() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier and fixed in v.5.0 allows attackers to cau… |
| CVE-2026-79602 | NONE | — | 2026-09-08 | A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen. | |
| CVE-2026-77106 | NONE | Patched | — | 2026-09-08 | Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvaul… |
| CVE-2026-77089 | NONE | Patched | — | 2026-09-08 | Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center. |
| CVE-2026-77091 | NONE | Patched | — | 2026-09-08 | DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and I… |
| CVE-2026-77092 | NONE | Patched | — | 2026-09-08 | Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Con… |
| CVE-2026-77097 | NONE | Patched | — | 2026-09-08 | Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved … |
| CVE-2026-77098 | NONE | Patched | — | 2026-09-08 | Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metric… |
| CVE-2026-62437 | NONE | — | 2026-09-08 | When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and the associated removal of trackin… | |
| CVE-2026-19203 | NONE | — | 2026-09-08 | A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, poten… | |
| CVE-2026-11573 | NONE | — | 2026-09-08 | Uncontrolled recursion in Qt's QDomDocument serialization (QtXml) lets deeply nested untrusted XML crash the app via stack exhaustion (DoS only). | |
| CVE-2026-12611 | NONE | — | 2026-09-08 | A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole ser… | |
| CVE-2026-77654 | NONE | — | 2026-09-08 | Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Inj… | |
| CVE-2026-19614 | NONE | — | 2026-09-08 | The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3. | |
| CVE-2026-85400 | NONE | — | 2026-09-08 | Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This al… | |
| CVE-2026-86590 | NONE | Patched | — | 2026-09-08 | In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP… |