Search
31,862 CVEs
CVEs (31,862, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 31,862 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85201 | NONE | — | 2026-09-07 | In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Cont… | |
| CVE-2026-19204 | NONE | — | 2026-09-07 | A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exha… | |
| CVE-2026-84173 | NONE | — | 2026-09-07 | In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a… | |
| CVE-2026-84186 | NONE | — | 2026-09-07 | Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarde… | |
| CVE-2026-84732 | NONE | — | 2026-09-07 | Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a t… | |
| CVE-2026-14297 | NONE | — | 2026-09-07 | A buffer overflow in the Bluetooth Continuous Glucose Monitoring Service (CGMS) Record Access Control Point (RACP) write handler allows an authenticated BLE peer … | |
| CVE-2026-18796 | NONE | — | 2026-09-07 | Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally st… | |
| CVE-2026-81738 | NONE | — | 2026-09-07 | OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries | |
| CVE-2026-81830 | NONE | — | 2026-09-07 | The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file… | |
| CVE-2026-82312 | NONE | — | 2026-09-07 | OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on named IPC objects | |
| CVE-2026-84226 | NONE | — | 2026-09-07 | OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps | |
| CVE-2026-84256 | NONE | — | 2026-09-07 | An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a c… | |
| CVE-2026-78043 | NONE | — | 2026-09-07 | The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbit… | |
| CVE-2026-78221 | NONE | — | 2026-09-07 | An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or d… | |
| CVE-2026-16876 | NONE | — | 2026-09-07 | An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering… | |
| CVE-2026-82751 | NONE | Patched | — | 2026-09-06 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a lar… |
| CVE-2026-82750 | NONE | Patched | — | 2026-09-06 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a lar… |
| CVE-2026-86283 | NONE | — | 2026-09-06 | MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access … | |
| CVE-2026-76160 | NONE | — | 2026-09-05 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-76161 | NONE | — | 2026-09-05 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-67277 | NONE | Patched | — | 2026-09-05 | RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start a… |
| CVE-2026-67278 | NONE | Patched | — | 2026-09-05 | MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirect… |
| CVE-2026-67279 | NONE | Patched | — | 2026-09-05 | RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a… |
| CVE-2026-67281 | NONE | Patched | — | 2026-09-05 | RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer use… |
| CVE-2026-86060 | NONE | Patched | — | 2026-09-05 | RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask … |