Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 376–400 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-0799 HIGH 8.7 2026-09-05 In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF inter…
CVE-2026-86193 NONE Patched — 2026-09-05 grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts…
CVE-2026-86195 NONE Patched — 2026-09-05 grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested supe…
CVE-2026-86196 NONE Patched — 2026-09-05 Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redi…
CVE-2026-86123 HIGH 8.7 2026-09-05 SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified…
CVE-2026-46636 NONE Patched — 2026-09-04 Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instan…
CVE-2026-85781 HIGH Patched 8.7 2026-09-04 Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with…
CVE-2026-53758 NONE — 2026-09-04 Emlog is an open source website building system. In versions 2.6.29 and prior, article content is processed by Parsedown without enabling safe mode, which means raw HTML in…
CVE-2026-79707 NONE — 2026-09-04 A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote …
CVE-2026-57445 NONE — 2026-09-03 Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In …
CVE-2026-53924 NONE Patched — 2026-09-03 Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. Pri…
CVE-2026-71404 HIGH Patched 8.7 2026-09-03 A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation an…
CVE-2026-85169 NONE Patched — 2026-09-03 n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox escape in the $fromAI handler. $fromAI resolved a caller-supplied placeholder name without re…
CVE-2026-79679 HIGH Patched 8.7 2026-09-03 Use of Weak Credentials vulnerability in B&R Industrial Automation GmbH mapp Audit used in mapp Services. This issue affects mapp Audit used in mapp Services: before 6.8.0.
CVE-2026-80465 HIGH 8.7 2026-09-03 A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (&hellip;
CVE-2026-77999 NONE &mdash; 2026-09-03 Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - The Pay&hellip;
CVE-2026-79756 NONE Patched &mdash; 2026-09-02 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, the fix for unauthenticated OS command injection in the nuclio dashboa&hellip;
CVE-2026-79989 NONE &mdash; 2026-09-02 The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the&hellip;
CVE-2026-79990 NONE &mdash; 2026-09-02 Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the&hellip;
CVE-2026-84695 HIGH Patched 8.7 2026-09-02 BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without c&hellip;
CVE-2026-84304 NONE Patched &mdash; 2026-09-01 gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBu&hellip;
CVE-2024-7952 NONE &mdash; 2026-09-01 A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be reached without authenticatio&hellip;
CVE-2024-7953 NONE &mdash; 2026-09-01 A vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a threat actor could creat&hellip;
CVE-2026-83616 NONE Patched &mdash; 2026-09-01 xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom &hellip;
CVE-2026-83617 NONE Patched &mdash; 2026-09-01 xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.11 until 0.9.12, the requireWellFormed: true element and &hellip;