Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 401–425 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-18313 MEDIUM 4.3 2026-09-05 rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it l…
CVE-2026-86191 MEDIUM 4.3 2026-09-05 SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attr…
CVE-2026-15550 MEDIUM 4.3 2026-09-05 The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability …
CVE-2026-86176 MEDIUM 4.3 2026-09-05 NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users wit…
CVE-2026-86174 MEDIUM 4.3 2026-09-05 Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrar…
CVE-2026-86118 MEDIUM Patched 4.3 2026-09-05 gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attacker…
CVE-2026-86120 MEDIUM 4.3 2026-09-05 APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission look…
CVE-2026-75018 MEDIUM 4.3 2026-09-05 The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16. This is due to the plugin not properly verif…
CVE-2026-81423 MEDIUM Patched 4.3 2026-09-05 The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect…
CVE-2026-83628 MEDIUM 4.3 2026-09-05 The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 on Multisite installations. This is due to the `tml_…
CVE-2026-18076 MEDIUM 4.3 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak.
CVE-2026-18078 MEDIUM 4.3 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow.
CVE-2026-17483 MEDIUM 4.3 2026-09-04 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure.
CVE-2026-17255 MEDIUM 4.3 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements.
CVE-2026-17259 MEDIUM 4.3 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow.
CVE-2026-17270 MEDIUM 4.3 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow.
CVE-2026-16941 MEDIUM 4.3 2026-09-04 IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization.
CVE-2026-85676 MEDIUM 4.3 2026-09-04 Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement. Attack…
CVE-2026-14466 MEDIUM 4.3 2026-09-04 It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject …
CVE-2026-19081 MEDIUM Patched 4.3 2026-09-04 Missing Authorization vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affect…
CVE-2026-85579 MEDIUM Patched 4.3 2026-09-04 SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The…
CVE-2026-19043 MEDIUM Patched 4.3 2026-09-04 Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Menulux Por…
CVE-2026-85407 MEDIUM 4.3 2026-09-04 A vulnerability was found in Eleveo Quality Management 9.7.0. This issue affects some unknown processing of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the c&hellip;
CVE-2026-85408 MEDIUM 4.3 2026-09-04 A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the compone&hellip;
CVE-2026-85382 MEDIUM 4.3 2026-09-04 A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Impacted is the function htmlspecialchars_d&hellip;