Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 2,372 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85230 | NONE | — | 2026-09-03 | A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widget URLs were validated only when the widget was rende… | |
| CVE-2026-85216 | NONE | — | 2026-09-03 | MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The cust… | |
| CVE-2026-85199 | NONE | Patched | — | 2026-09-03 | Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path traversal vulnerability in the REST API. User-controlled identifiers used to create, update, or dele… |
| CVE-2026-82180 | NONE | — | 2026-09-03 | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, CertificateMqttFilter parses an X.509 certificate… | |
| CVE-2026-80515 | NONE | — | 2026-09-03 | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by callin… | |
| CVE-2026-6071 | NONE | — | 2026-09-03 | A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated objec… | |
| CVE-2026-9854 | NONE | — | 2026-09-03 | A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying W… | |
| CVE-2026-9852 | NONE | — | 2026-09-03 | A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, dep… | |
| CVE-2026-9853 | NONE | — | 2026-09-03 | A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects wi… | |
| CVE-2026-85167 | NONE | Patched | — | 2026-09-03 | n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsearch Document Get All and Google Cloud Firestore Document Query operation… |
| CVE-2026-85168 | NONE | Patched | — | 2026-09-03 | n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code execution vulnerability in the Git node. The node reset a fixed list of command-bearing configuration… |
| CVE-2026-85169 | NONE | Patched | — | 2026-09-03 | n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox escape in the $fromAI handler. $fromAI resolved a caller-supplied placeholder name without re… |
| CVE-2026-85170 | NONE | Patched | — | 2026-09-03 | n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail composer without verifying it is a string. An authentica… |
| CVE-2026-85171 | NONE | Patched | — | 2026-09-03 | n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailcheck nodes. These nodes send their decrypted credenti… |
| CVE-2026-85172 | NONE | Patched | — | 2026-09-03 | n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper function exposed to Code and Function nodes. The validation logi… |
| CVE-2026-85173 | NONE | Patched | — | 2026-09-03 | n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to acce… |
| CVE-2026-85165 | NONE | Patched | — | 2026-09-03 | n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions reso… |
| CVE-2026-85166 | NONE | Patched | — | 2026-09-03 | n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline workflow JSON of nodes that execute an inline sub-workflow (e.g., the Workf… |
| CVE-2026-84830 | NONE | Patched | — | 2026-09-03 | SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges. |
| CVE-2026-84831 | NONE | Patched | — | 2026-09-03 | SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the pas… |
| CVE-2026-84832 | NONE | Patched | — | 2026-09-03 | SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privi… |
| CVE-2026-80755 | NONE | — | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: selinux: reject a permission value exceeding the class permission count perm_read() bounds a permissio… | |
| CVE-2026-80756 | NONE | — | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: selinux: do not cancel a policy conversion that never started sel_write_load() calls selinux_policy_ca… | |
| CVE-2026-80757 | NONE | — | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: selinux: reject a class permission count below its inherited common security_get_permissions() maps an… | |
| CVE-2026-80746 | NONE | — | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: clk: qcom: dispcc-eliza: Fix disp_cc_mdss_mdp_clk_src RCG stall on Eliza EVK Eliza EVK (eliza-cqs-evk.… |