Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 376–400 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-85230 NONE — 2026-09-03 A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widget URLs were validated only when the widget was rende…
CVE-2026-85216 NONE — 2026-09-03 MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The cust…
CVE-2026-85199 NONE Patched — 2026-09-03 Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path traversal vulnerability in the REST API. User-controlled identifiers used to create, update, or dele…
CVE-2026-82180 NONE — 2026-09-03 In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, CertificateMqttFilter parses an X.509 certificate…
CVE-2026-80515 NONE — 2026-09-03 In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by callin…
CVE-2026-6071 NONE — 2026-09-03 A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated objec…
CVE-2026-9854 NONE — 2026-09-03 A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying W…
CVE-2026-9852 NONE — 2026-09-03 A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, dep…
CVE-2026-9853 NONE — 2026-09-03 A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects wi…
CVE-2026-85167 NONE Patched — 2026-09-03 n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsearch Document Get All and Google Cloud Firestore Document Query operation…
CVE-2026-85168 NONE Patched — 2026-09-03 n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code execution vulnerability in the Git node. The node reset a fixed list of command-bearing configuration…
CVE-2026-85169 NONE Patched — 2026-09-03 n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox escape in the $fromAI handler. $fromAI resolved a caller-supplied placeholder name without re…
CVE-2026-85170 NONE Patched — 2026-09-03 n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail composer without verifying it is a string. An authentica…
CVE-2026-85171 NONE Patched — 2026-09-03 n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailcheck nodes. These nodes send their decrypted credenti…
CVE-2026-85172 NONE Patched — 2026-09-03 n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper function exposed to Code and Function nodes. The validation logi…
CVE-2026-85173 NONE Patched — 2026-09-03 n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to acce…
CVE-2026-85165 NONE Patched — 2026-09-03 n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions reso…
CVE-2026-85166 NONE Patched — 2026-09-03 n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline workflow JSON of nodes that execute an inline sub-workflow (e.g., the Workf…
CVE-2026-84830 NONE Patched — 2026-09-03 SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges.
CVE-2026-84831 NONE Patched — 2026-09-03 SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the pas…
CVE-2026-84832 NONE Patched — 2026-09-03 SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privi…
CVE-2026-80755 NONE — 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: selinux: reject a permission value exceeding the class permission count perm_read() bounds a permissio…
CVE-2026-80756 NONE — 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: selinux: do not cancel a policy conversion that never started sel_write_load() calls selinux_policy_ca…
CVE-2026-80757 NONE — 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: selinux: reject a class permission count below its inherited common security_get_permissions() maps an…
CVE-2026-80746 NONE — 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: clk: qcom: dispcc-eliza: Fix disp_cc_mdss_mdp_clk_src RCG stall on Eliza EVK Eliza EVK (eliza-cqs-evk.…