Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

13,088 CVEs

CVEs (13,088, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 401–425 of 13,088 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-80739 NONE — 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock In case __mlx5e_add_fdb_flow() fails…
CVE-2026-80740 NONE — 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: drm/log: Fix infinite loop when scale is too large for display When scale is large enough that scaled_…
CVE-2026-80742 NONE — 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: af_packet: Don't send zero-byte data in tpacket_snd(). syzbot reported a WARNING in __dev_queue_xmit()…
CVE-2026-80743 NONE — 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers The irq handlers take a struct device p…
CVE-2026-80744 NONE — 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path In nft_flow_rule_offload_…
CVE-2026-80733 NONE — 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: net: remove WARN_ON_ONCE() from sk_mc_loop() sk_mc_loop() can be called for sockets that are neither A…
CVE-2026-80727 NONE — 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: x86/mce: Set up the polling timer before CMCI discovery I hit the following on one of my machines: …
CVE-2026-80728 NONE — 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: Revert "drm/amdgpu: fix aperture mapping leak" devres teardown is LIFO. The aperture devres node was r…
CVE-2026-80729 NONE — 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: initialise workingset state before folio split xas_try_split() adds __GFP_ACCOUNT for …
CVE-2026-80730 NONE — 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix crash passing ERR_PTR to kthread_stop() In test_ringbuffer()'s out_free cleanup loop,…
CVE-2026-78064 NONE — 2026-09-03 Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inherited FOF `save` task in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `fof.xml` grants the …
CVE-2026-78065 NONE — 2026-09-03 Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated user (IDOR) in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `editAddress()` …
CVE-2026-78069 NONE — 2026-09-03 Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `J2StoreControllerApps`'s…
CVE-2026-78080 NONE &mdash; 2026-09-03 Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used in queries without validation, allowing SQLi vectors.
CVE-2026-78304 NONE &mdash; 2026-09-03 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-76176 NONE &mdash; 2026-09-03 SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the selected_gr&hellip;
CVE-2026-76177 NONE &mdash; 2026-09-03 Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate endpoint due to insufficient validation of the HTTPS_SERV and FILE_SERV paramete&hellip;
CVE-2026-76178 NONE &mdash; 2026-09-03 A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification. A user with administrator p&hellip;
CVE-2026-77999 NONE &mdash; 2026-09-03 Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - The Pay&hellip;
CVE-2026-78000 NONE &mdash; 2026-09-03 Joomla Extension - j2commerce.com - Reflected XSS via `filter_tag`, `pricefrom` and `priceto` in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - Four task handlers accept&hellip;
CVE-2026-76174 NONE &mdash; 2026-09-03 Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The application validates files solely based on the name &hellip;
CVE-2026-76175 NONE &mdash; 2026-09-03 SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list endpoint. Input provided by an authenticated user with operator privileg&hellip;
CVE-2026-15926 NONE &mdash; 2026-09-03 Rejected reason: Red Hat Product Security has determined that this CVE ID is not needed
CVE-2026-15933 NONE Patched &mdash; 2026-09-03 OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can view previously configured service passwords, includ&hellip;
CVE-2026-66048 NONE &mdash; 2026-09-03 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.