Search
13,088 CVEs
CVEs (13,088, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 13,088 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85640 | MEDIUM | 6.3 | 2026-09-07 | Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component | |
| CVE-2026-85639 | MEDIUM | 5.6 | 2026-09-04 | A security vulnerability has been detected in jofpin trape 2.0. This vulnerability affects unknown code of the file core/user.py of the component Telemetry Endpoint. Such m… | |
| CVE-2026-85638 | HIGH | 7.3 | 2026-09-04 | A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. This manipulation of the argument vId/id causes authorization byp… | |
| CVE-2026-85637 | MEDIUM | 5.3 | 2026-09-04 | A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affected by this issue is the function join_room of the file core/sockets.py of the component Admin Endpoint.… | |
| CVE-2026-85636 | MEDIUM | 5.3 | 2026-09-04 | A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerability is an unknown functionality of the file core/stats.py of the component Login Endpoint. … | |
| CVE-2026-85626 | HIGH | 7.5 | 2026-09-04 | git-mcp-server 2.15.1 contains an argument injection vulnerability in the ref and object parameters of git_log, git_diff, and git_show tools that lack leading-dash validati… | |
| CVE-2026-85625 | HIGH | 8.1 | 2026-09-04 | sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain, and dispatches any matched operator key including $where. The $where oper… | |
| CVE-2026-85624 | MEDIUM | 6.5 | 2026-09-04 | Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in the noteReferenceList procedure that performs no ownership verification on supplied note identif… | |
| CVE-2026-85623 | HIGH | 8.8 | 2026-09-04 | goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection. Attackers can distribute malicious recipes that execute … | |
| CVE-2026-85622 | MEDIUM | 5.3 | 2026-09-04 | AppFlowy-Cloud through 0.9.64 fails to validate workspace membership when establishing WebSocket connections in the establish_ws_connection_v2 handler, allowing authenticat… | |
| CVE-2026-85621 | MEDIUM | 6.5 | 2026-09-04 | LobeChat (LobeHub) 2.2.1 does not properly verify inbound chat-platform webhook signatures in the QQ and Feishu adapters. The webhook route (/api/agent/webhooks/:platform) … | |
| CVE-2026-85620 | HIGH | 8.6 | 2026-09-04 | Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. Attackers can e… | |
| CVE-2026-85619 | HIGH | 7.5 | 2026-09-04 | AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization checks, allowing attackers to access documents and database row… | |
| CVE-2026-85618 | MEDIUM | 6.5 | 2026-09-04 | ConvertX 0.17.0 contains an arbitrary file read vulnerability in the xelatex converter that allows authenticated users to read files by uploading LaTeX files with input dir… | |
| CVE-2026-85617 | HIGH | Patched | 8.8 | 2026-09-04 | snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside thei… |
| CVE-2026-85616 | HIGH | Patched | 8.5 | 2026-09-04 | Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authentica… |
| CVE-2026-85615 | MEDIUM | Patched | 6.4 | 2026-09-04 | Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to bind dashboar… |
| CVE-2026-85614 | HIGH | Patched | 8.6 | 2026-09-04 | OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled … |
| CVE-2026-85613 | HIGH | Patched | 8.2 | 2026-09-04 | OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute… |
| CVE-2026-85612 | HIGH | Patched | 7.5 | 2026-09-04 | OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied ur… |
| CVE-2026-85611 | MEDIUM | Patched | 6.4 | 2026-09-04 | OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to … |
| CVE-2026-85610 | HIGH | Patched | 8.8 | 2026-09-04 | OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering… |
| CVE-2026-85609 | HIGH | Patched | 7.5 | 2026-09-04 | Openpanel before 2.3.0 contains an unauthenticated full-read server-side request forgery (SSRF) vulnerability in the GET /tools/site-checker endpoint (apps/api/src/controll… |
| CVE-2026-85608 | HIGH | 7.5 | 2026-09-04 | Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthen… | |
| CVE-2026-85607 | HIGH | 8.8 | 2026-09-04 | Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/r… |