Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 376–400 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-48019 HIGH Patched 8.9 2026-09-04 Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony…
CVE-2026-4813 NONE — 2026-09-01 A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticated administrators to execute code remotely. The XML/XSLT proces…
CVE-2026-48486 HIGH Patched 7.5 2026-09-03 Signum Node is a HDD-mined cryptocurrency using an energy efficient and fair Proof-of-Commitment (PoC+) consensus algorithm. Prior to version 3.9.9, an integer overflow in …
CVE-2026-48888 HIGH Patched 7.5 2026-09-08 Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0.
CVE-2026-48932 LOW 3.7 2026-09-01 A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` he…
CVE-2026-49249 NONE Patched — 2026-09-02 Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.10.0, Boruta…
CVE-2026-49329 HIGH 7.5 2026-09-01 A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language.ParseAcce…
CVE-2026-4945 MEDIUM 5.3 2026-09-07 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a…
CVE-2026-49455 MEDIUM Patched 6.5 2026-09-03 Waku is the minimal React framework. Prior to version 1.0.0-beta.1, Waku's RSC request dispatcher invokes server actions without validating the request's Origin (or Sec-Fet…
CVE-2026-49456 LOW Patched 3.1 2026-09-03 Waku is the minimal React framework. Prior to version 1.0.0-beta.1, the unstable_redirect() helper exported from waku/router/server (packages/waku/src/router/define-router.…
CVE-2026-49509 MEDIUM 4.4 2026-09-04 Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers. This issue affects rLottie: 25648aef19187b3f87f4d9420b8d761453ad4630.
CVE-2026-49830 MEDIUM Patched 4.4 2026-09-02 DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, when ingesting an a…
CVE-2026-49831 MEDIUM Patched 5.5 2026-09-02 DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, the Curation Task f…
CVE-2026-49832 HIGH Patched 8.0 2026-09-02 DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before …
CVE-2026-49833 MEDIUM Patched 5.5 2026-09-02 DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, 9.0-rc1 to before 9.3, and …
CVE-2026-50093 CRITICAL 9.0 2026-09-08 A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Co&hellip;
CVE-2026-50553 NONE Patched &mdash; 2026-09-04 Note Mark is an open-source note-taking application. Prior to version 0.19.5, Note Mark validates book and note slug values with the OpenAPI/huma tag pattern:"[a-z0-9-]+". &hellip;
CVE-2026-50554 MEDIUM Patched 5.3 2026-09-03 Note Mark is an open-source note-taking application. Prior to version 0.19.5, GET /api/books/{bookID}/notes is an unauthenticated endpoint that accepts a "deleted" query pa&hellip;
CVE-2026-50894 NONE &mdash; 2026-09-04 easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to ex&hellip;
CVE-2026-51741 CRITICAL 9.8 2026-09-01 Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a craft&hellip;
CVE-2026-51742 MEDIUM 5.9 2026-09-01 Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger WAN discovery logic via sending a craf&hellip;
CVE-2026-51743 CRITICAL 9.1 2026-09-01 Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via se&hellip;
CVE-2026-51744 CRITICAL 9.8 2026-09-01 Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronizati&hellip;
CVE-2026-51745 MEDIUM 5.3 2026-09-01 Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the primary station list via send&hellip;
CVE-2026-51747 CRITICAL 9.8 2026-09-01 Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh heartbeat information toward &hellip;