Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 2,372 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85577 | MEDIUM | 5.4 | 2026-09-04 | AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScrip… | |
| CVE-2026-85547 | NONE | — | 2026-09-04 | A cross-site request forgery (CSRF) vulnerability exists in MISP due to form-security and CSRF protections being disabled based on whether an incoming request was identifie… | |
| CVE-2026-85546 | NONE | — | 2026-09-04 | MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions sh… | |
| CVE-2026-85541 | MEDIUM | 5.4 | 2026-09-04 | DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browse… | |
| CVE-2026-85540 | HIGH | 8.8 | 2026-09-04 | DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents. | |
| CVE-2026-85538 | NONE | — | 2026-09-04 | An incorrect authorization vulnerability in MISP allowed authenticated users to delete attributes from events despite lacking the required perm_modify or perm_modify_org pe… | |
| CVE-2026-85534 | MEDIUM | 5.9 | 2026-09-04 | A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control win… | |
| CVE-2026-85533 | NONE | — | 2026-09-04 | An authorization flaw in MISP allowed an authenticated user to submit a sharing_group_id without verifying that the user was authorized to use the referenced Sharing Group.… | |
| CVE-2026-85528 | MEDIUM | 5.3 | 2026-09-04 | Improper input validation of the auto-configuration account identifier in Snowflake JDBC Driver versions 4.2.0 through 4.3.3 allowed a credential-bearing login request to b… | |
| CVE-2026-85525 | HIGH | 7.4 | 2026-09-04 | Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses w… | |
| CVE-2026-85522 | MEDIUM | 5.3 | 2026-09-04 | A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function createSlotImportJob of the file src/cluster_migrateslots.… | |
| CVE-2026-85517 | MEDIUM | 5.3 | 2026-09-04 | A flaw has been found in code-projects Vehicle Management System 1.0. The impacted element is an unknown function of the file /vehicle_management.sql of the component SQL D… | |
| CVE-2026-85516 | HIGH | 7.3 | 2026-09-04 | A vulnerability was detected in code-projects Vehicle Management System 1.0. The affected element is an unknown function of the file /busprofile.php. Performing a manipulat… | |
| CVE-2026-85514 | MEDIUM | 6.3 | 2026-09-04 | A security vulnerability has been detected in StackStorm st2 up to 3.9.0. Impacted is an unknown function of the file st2api/st2api/controllers/v1/auth.py of the component … | |
| CVE-2026-85513 | MEDIUM | 6.3 | 2026-09-04 | A weakness has been identified in StackStorm st2 up to 3.9.0. This issue affects the function assert_user_is_admin_if_user_query_param_is_provided of the file st2api/st2api… | |
| CVE-2026-85512 | HIGH | 7.3 | 2026-09-04 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The man… | |
| CVE-2026-85509 | CRITICAL | Patched | 9.8 | 2026-09-04 | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested. |
| CVE-2026-85508 | CRITICAL | Patched | 9.8 | 2026-09-04 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell… |
| CVE-2026-85507 | CRITICAL | Patched | 9.8 | 2026-09-04 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info). |
| CVE-2026-85506 | CRITICAL | Patched | 9.8 | 2026-09-04 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-syst… |
| CVE-2026-85505 | HIGH | Patched | 7.5 | 2026-09-04 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short… |
| CVE-2026-85504 | CRITICAL | Patched | 9.8 | 2026-09-04 | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malfo… |
| CVE-2026-85458 | NONE | — | 2026-09-03 | Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height. | |
| CVE-2026-85456 | MEDIUM | 5.5 | 2026-09-03 | MOOS-IvP through 24.8.1 fails to properly validate variable names extracted from alog files in the SplitHandler, allowing attackers to write files outside the split directo… | |
| CVE-2026-85455 | HIGH | 8.2 | 2026-09-03 | MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization… |