Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 2,372 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0799 | HIGH | 8.7 | 2026-09-05 | In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF inter… | |
| CVE-2026-86193 | NONE | Patched | — | 2026-09-05 | grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts… |
| CVE-2026-86195 | NONE | Patched | — | 2026-09-05 | grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested supe… |
| CVE-2026-86196 | NONE | Patched | — | 2026-09-05 | Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redi… |
| CVE-2026-86123 | HIGH | 8.7 | 2026-09-05 | SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified… | |
| CVE-2026-46636 | NONE | Patched | — | 2026-09-04 | Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instan… |
| CVE-2026-85781 | HIGH | Patched | 8.7 | 2026-09-04 | Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with… |
| CVE-2026-53758 | NONE | — | 2026-09-04 | Emlog is an open source website building system. In versions 2.6.29 and prior, article content is processed by Parsedown without enabling safe mode, which means raw HTML in… | |
| CVE-2026-79707 | NONE | — | 2026-09-04 | A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote … | |
| CVE-2026-57445 | NONE | — | 2026-09-03 | Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In … | |
| CVE-2026-53924 | NONE | Patched | — | 2026-09-03 | Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. Pri… |
| CVE-2026-71404 | HIGH | Patched | 8.7 | 2026-09-03 | A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation an… |
| CVE-2026-85169 | NONE | Patched | — | 2026-09-03 | n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox escape in the $fromAI handler. $fromAI resolved a caller-supplied placeholder name without re… |
| CVE-2026-79679 | HIGH | Patched | 8.7 | 2026-09-03 | Use of Weak Credentials vulnerability in B&R Industrial Automation GmbH mapp Audit used in mapp Services. This issue affects mapp Audit used in mapp Services: before 6.8.0. |
| CVE-2026-80465 | HIGH | 8.7 | 2026-09-03 | A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (… | |
| CVE-2026-77999 | NONE | — | 2026-09-03 | Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - The Pay… | |
| CVE-2026-79756 | NONE | Patched | — | 2026-09-02 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, the fix for unauthenticated OS command injection in the nuclio dashboa… |
| CVE-2026-79989 | NONE | — | 2026-09-02 | The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the… | |
| CVE-2026-79990 | NONE | — | 2026-09-02 | Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the… | |
| CVE-2026-84695 | HIGH | Patched | 8.7 | 2026-09-02 | BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without c… |
| CVE-2026-84304 | NONE | Patched | — | 2026-09-01 | gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBu… |
| CVE-2024-7952 | NONE | — | 2026-09-01 | A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be reached without authenticatio… | |
| CVE-2024-7953 | NONE | — | 2026-09-01 | A vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a threat actor could creat… | |
| CVE-2026-83616 | NONE | Patched | — | 2026-09-01 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom … |
| CVE-2026-83617 | NONE | Patched | — | 2026-09-01 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.11 until 0.9.12, the requireWellFormed: true element and … |