Search
140,640 CVEs · High severity
CVEs (140,640, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 140,640 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85174 | HIGH | 8.8 | 2026-09-03 | SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated att… | |
| CVE-2026-85175 | HIGH | Patched | 8.8 | 2026-09-03 | SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.jso… |
| CVE-2026-85164 | HIGH | 7.1 | 2026-09-03 | WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set_api_userImages API endpoint that fails to validate profileImg and backg… | |
| CVE-2026-85155 | HIGH | 7.5 | 2026-09-03 | WWBN AVideo contains a SQL injection vulnerability in the sort column parameter of the get.json.php endpoint with APIName=channels that allows unauthenticated attackers to … | |
| CVE-2026-85160 | HIGH | 8.1 | 2026-09-03 | AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploi… | |
| CVE-2026-85105 | HIGH | 7.3 | 2026-09-03 | A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is the function _sess_nowait of the file s71.py of the component Session Management. This … | |
| CVE-2026-85124 | HIGH | Patched | 7.5 | 2026-09-03 | @fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. Th… |
| CVE-2026-85150 | HIGH | 7.5 | 2026-09-03 | A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses … | |
| CVE-2026-85091 | HIGH | 7.4 | 2026-09-03 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale ex… | |
| CVE-2026-80753 | HIGH | 8.4 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: ovpn: run deferred work on a module-owned workqueue ovpn queues several work items whose callbacks exe… | |
| CVE-2026-80754 | HIGH | 7.8 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - fix F55 transmitter electrode count typo During F55 sensor detection, the tran… | |
| CVE-2026-80745 | HIGH | 8.4 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: regulator: fp9931: Fix VPOS/VNEG voltage selector table The VPOSNEG_table[] mapping does not match the… | |
| CVE-2026-80747 | HIGH | 8.0 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add bounds check for CRAT subtype length The CRAT parser validates that the subtype header… | |
| CVE-2026-80748 | HIGH | 7.8 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: mmc: loongson2: Fix sg iteration in data reorder functions In ls2k0500_mmc_reorder_cmd_data() and ls2k… | |
| CVE-2026-80749 | HIGH | 7.1 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: drm/connector/hdmi: Fix out of bounds memory read A helper function was copying a given audio infofram… | |
| CVE-2026-80750 | HIGH | 8.4 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix remaining %pOF after of_node_put() scpsys_get_bus_protection_legacy() looks up… | |
| CVE-2026-80751 | HIGH | 7.8 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: mfg: initialize prev_o in mtk_mfg_attach_dev() mtk_mfg_attach_dev() reads prev_o o… | |
| CVE-2026-80752 | HIGH | 8.4 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: Input: psxpad-spi - set driver data before use psxpad_spi_suspend() retrieves the controller state wit… | |
| CVE-2026-80741 | HIGH | 7.1 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: drm/log: Fix out-of-bounds read on empty message length drm_log_draw_kmsg_record() accesses s[len - 1]… | |
| CVE-2026-80734 | HIGH | 8.8 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: btrfs: initialize inode mapping flags for cached inodes [BUG] When running generic/795 with 8K block s… | |
| CVE-2026-80735 | HIGH | 7.3 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: ovpn: ensure socket is owned by ovpn before deref sk_user_data Some subsystems, like BPF SOCKMAP, set … | |
| CVE-2026-80736 | HIGH | 7.8 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Fix bandwidth group reservation indexing Valid bandwidth group IDs range from 1 through M… | |
| CVE-2026-80737 | HIGH | 7.8 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: serial: amba-pl011: synchronize DMA teardown dmaengine_terminate_all() does not wait for a running cal… | |
| CVE-2026-80738 | HIGH | 7.3 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie bpf_tcp_gen_syncookie and bpf_tcp_check_… | |
| CVE-2026-80731 | HIGH | 7.8 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header dev_validate_header() reads dev->hard_he… |