Search
13,088 CVEs
CVEs (13,088, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 13,088 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-80739 | NONE | — | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock In case __mlx5e_add_fdb_flow() fails… | |
| CVE-2026-80740 | NONE | — | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: drm/log: Fix infinite loop when scale is too large for display When scale is large enough that scaled_… | |
| CVE-2026-80742 | NONE | — | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: af_packet: Don't send zero-byte data in tpacket_snd(). syzbot reported a WARNING in __dev_queue_xmit()… | |
| CVE-2026-80743 | NONE | — | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers The irq handlers take a struct device p… | |
| CVE-2026-80744 | NONE | — | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path In nft_flow_rule_offload_… | |
| CVE-2026-80733 | NONE | — | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: net: remove WARN_ON_ONCE() from sk_mc_loop() sk_mc_loop() can be called for sockets that are neither A… | |
| CVE-2026-80727 | NONE | — | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: x86/mce: Set up the polling timer before CMCI discovery I hit the following on one of my machines: … | |
| CVE-2026-80728 | NONE | — | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: Revert "drm/amdgpu: fix aperture mapping leak" devres teardown is LIFO. The aperture devres node was r… | |
| CVE-2026-80729 | NONE | — | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: initialise workingset state before folio split xas_try_split() adds __GFP_ACCOUNT for … | |
| CVE-2026-80730 | NONE | — | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix crash passing ERR_PTR to kthread_stop() In test_ringbuffer()'s out_free cleanup loop,… | |
| CVE-2026-78064 | NONE | — | 2026-09-03 | Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inherited FOF `save` task in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `fof.xml` grants the … | |
| CVE-2026-78065 | NONE | — | 2026-09-03 | Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated user (IDOR) in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `editAddress()` … | |
| CVE-2026-78069 | NONE | — | 2026-09-03 | Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `J2StoreControllerApps`'s… | |
| CVE-2026-78080 | NONE | — | 2026-09-03 | Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used in queries without validation, allowing SQLi vectors. | |
| CVE-2026-78304 | NONE | — | 2026-09-03 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-76176 | NONE | — | 2026-09-03 | SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the selected_gr… | |
| CVE-2026-76177 | NONE | — | 2026-09-03 | Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate endpoint due to insufficient validation of the HTTPS_SERV and FILE_SERV paramete… | |
| CVE-2026-76178 | NONE | — | 2026-09-03 | A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification. A user with administrator p… | |
| CVE-2026-77999 | NONE | — | 2026-09-03 | Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - The Pay… | |
| CVE-2026-78000 | NONE | — | 2026-09-03 | Joomla Extension - j2commerce.com - Reflected XSS via `filter_tag`, `pricefrom` and `priceto` in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - Four task handlers accept… | |
| CVE-2026-76174 | NONE | — | 2026-09-03 | Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The application validates files solely based on the name … | |
| CVE-2026-76175 | NONE | — | 2026-09-03 | SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list endpoint. Input provided by an authenticated user with operator privileg… | |
| CVE-2026-15926 | NONE | — | 2026-09-03 | Rejected reason: Red Hat Product Security has determined that this CVE ID is not needed | |
| CVE-2026-15933 | NONE | Patched | — | 2026-09-03 | OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can view previously configured service passwords, includ… |
| CVE-2026-66048 | NONE | — | 2026-09-03 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |