Search
78,575 CVEs
CVEs (78,575, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 78,575 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9508 | NONE | — | 2026-05-29 | Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when the administra… | |
| CVE-2026-9507 | NONE | — | 2026-06-16 | A session fixation vulnerability has been identified in osTicket v1.18.2. This security flaw allows an attacker to hijack a victim’s account by keeping the initial session … | |
| CVE-2026-9506 | NONE | — | 2026-06-08 | This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remote attacker could explo… | |
| CVE-2026-9504 | LOW | 3.3 | 2026-05-25 | A weakness has been identified in GNU LibreDWG up to 0.14. Affected is the function bit_convert_TU of the file programs/dwggrep.c of the component Dwggrep Utility. This man… | |
| CVE-2026-9503 | LOW | 3.3 | 2026-05-25 | A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file src/decode.c of the component DWG File Handler. The ma… | |
| CVE-2026-9502 | MEDIUM | 5.3 | 2026-05-25 | A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. The… | |
| CVE-2026-9501 | LOW | 3.3 | 2026-05-25 | A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section of the file src/decode.c of the component Dwgread U… | |
| CVE-2026-9500 | MEDIUM | 5.3 | 2026-05-25 | A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgread Ut… | |
| CVE-2026-9499 | NONE | — | 2026-07-21 | An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated … | |
| CVE-2026-9498 | MEDIUM | 6.3 | 2026-05-25 | A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass of the component Message Template Handler. Such mani… | |
| CVE-2026-9497 | MEDIUM | 6.3 | 2026-05-25 | A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This ma… | |
| CVE-2026-9496 | HIGH | Patched | 7.5 | 2026-05-26 | Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerabilit… |
| CVE-2026-9495 | HIGH | Patched | 7.3 | 2026-05-26 | Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control Bypass due to the middleware being silently dropped from the execution ch… |
| CVE-2026-9494 | MEDIUM | 5.5 | 2026-07-16 | An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executin… | |
| CVE-2026-9493 | MEDIUM | 6.5 | 2026-05-29 | Service Center developed by BankPro E-Service Technology has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify the parame… | |
| CVE-2026-9492 | HIGH | 7.8 | 2026-07-13 | The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated… | |
| CVE-2026-9491 | MEDIUM | Patched | 4.3 | 2026-08-28 | A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive information. |
| CVE-2026-9490 | MEDIUM | Patched | 5.5 | 2026-05-25 | A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This vulnerability allows an… |
| CVE-2026-9489 | NONE | Patched | — | 2026-05-25 | NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke inter… |
| CVE-2026-9487 | CRITICAL | Patched | 9.1 | 2026-08-03 | XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolves the SignedInfo Refere… |
| CVE-2026-9486 | MEDIUM | 4.3 | 2026-05-25 | A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part. The manipulation results in cross-site request for… | |
| CVE-2026-9485 | LOW | 3.5 | 2026-05-25 | A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some unknown functionality of the file students.php. The ma… | |
| CVE-2026-9484 | MEDIUM | 6.3 | 2026-05-25 | A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFrom… | |
| CVE-2026-9483 | MEDIUM | 6.3 | 2026-05-25 | A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the file grades.php. Performing a manipulation of the a… | |
| CVE-2026-9482 | HIGH | 8.8 | 2026-05-25 | A vulnerability has been found in Edimax EW-7438RPn 1.31. This impacts the function formSDHCP of the file /goform/formSDHCP. Such manipulation of the argument submit-url le… |