Search
80,425 CVEs
CVEs (80,425, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 80,425 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77132 | NONE | — | 2026-09-08 | It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged … | |
| CVE-2026-75811 | NONE | — | 2026-09-08 | Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause h… | |
| CVE-2026-18023 | NONE | — | 2026-09-08 | Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via … | |
| CVE-2026-19397 | NONE | — | 2026-09-08 | Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the… | |
| CVE-2026-75808 | NONE | — | 2026-09-08 | Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by by… | |
| CVE-2026-75809 | NONE | — | 2026-09-08 | Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver au… | |
| CVE-2026-75810 | NONE | — | 2026-09-08 | Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigg… | |
| CVE-2026-12962 | NONE | — | 2026-09-08 | A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a … | |
| CVE-2026-16003 | NONE | — | 2026-09-08 | Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IO… | |
| CVE-2026-16004 | NONE | — | 2026-09-08 | Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL reques… | |
| CVE-2026-16005 | NONE | — | 2026-09-08 | Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verificat… | |
| CVE-2026-16006 | NONE | — | 2026-09-08 | Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCT… | |
| CVE-2026-82710 | NONE | Patched | — | 2026-09-08 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control seque… |
| CVE-2026-82758 | NONE | Patched | — | 2026-09-07 | Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client … |
| CVE-2026-82586 | NONE | Patched | — | 2026-09-07 | Improper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list… |
| CVE-2026-82753 | NONE | Patched | — | 2026-09-07 | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to exhaust database st… |
| CVE-2026-82754 | NONE | Patched | — | 2026-09-07 | Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefi… |
| CVE-2026-82755 | NONE | Patched | — | 2026-09-07 | Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant's OAuth discovery… |
| CVE-2026-82756 | NONE | Patched | — | 2026-09-07 | Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication … |
| CVE-2026-82757 | NONE | Patched | — | 2026-09-07 | Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make t… |
| CVE-2026-81638 | NONE | Patched | — | 2026-09-07 | Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.… |
| CVE-2026-82584 | NONE | Patched | — | 2026-09-07 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project igniter allows a malicious package publisher to forge the mix igniter.install con… |
| CVE-2026-86426 | NONE | Patched | — | 2026-09-07 | LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeri… |
| CVE-2026-78325 | NONE | — | 2026-09-07 | Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the… | |
| CVE-2026-82325 | NONE | — | 2026-09-07 | A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages |