Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 2,372 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18313 | MEDIUM | 4.3 | 2026-09-05 | rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it l… | |
| CVE-2026-86191 | MEDIUM | 4.3 | 2026-09-05 | SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attr… | |
| CVE-2026-15550 | MEDIUM | 4.3 | 2026-09-05 | The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability … | |
| CVE-2026-86176 | MEDIUM | 4.3 | 2026-09-05 | NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users wit… | |
| CVE-2026-86174 | MEDIUM | 4.3 | 2026-09-05 | Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrar… | |
| CVE-2026-86118 | MEDIUM | Patched | 4.3 | 2026-09-05 | gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attacker… |
| CVE-2026-86120 | MEDIUM | 4.3 | 2026-09-05 | APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission look… | |
| CVE-2026-75018 | MEDIUM | 4.3 | 2026-09-05 | The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16. This is due to the plugin not properly verif… | |
| CVE-2026-81423 | MEDIUM | Patched | 4.3 | 2026-09-05 | The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect… |
| CVE-2026-83628 | MEDIUM | 4.3 | 2026-09-05 | The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 on Multisite installations. This is due to the `tml_… | |
| CVE-2026-18076 | MEDIUM | 4.3 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak. | |
| CVE-2026-18078 | MEDIUM | 4.3 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow. | |
| CVE-2026-17483 | MEDIUM | 4.3 | 2026-09-04 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure. | |
| CVE-2026-17255 | MEDIUM | 4.3 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements. | |
| CVE-2026-17259 | MEDIUM | 4.3 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow. | |
| CVE-2026-17270 | MEDIUM | 4.3 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow. | |
| CVE-2026-16941 | MEDIUM | 4.3 | 2026-09-04 | IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization. | |
| CVE-2026-85676 | MEDIUM | 4.3 | 2026-09-04 | Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement. Attack… | |
| CVE-2026-14466 | MEDIUM | 4.3 | 2026-09-04 | It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject … | |
| CVE-2026-19081 | MEDIUM | Patched | 4.3 | 2026-09-04 | Missing Authorization vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affect… |
| CVE-2026-85579 | MEDIUM | Patched | 4.3 | 2026-09-04 | SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The… |
| CVE-2026-19043 | MEDIUM | Patched | 4.3 | 2026-09-04 | Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Menulux Por… |
| CVE-2026-85407 | MEDIUM | 4.3 | 2026-09-04 | A vulnerability was found in Eleveo Quality Management 9.7.0. This issue affects some unknown processing of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the c… | |
| CVE-2026-85408 | MEDIUM | 4.3 | 2026-09-04 | A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the compone… | |
| CVE-2026-85382 | MEDIUM | 4.3 | 2026-09-04 | A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Impacted is the function htmlspecialchars_d… |