Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

565 CVEs · published 2026-09-24 to 2026-09-24

CVEs (565, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 401–425 of 565 (capped at 500)

CVE ID Severity Patch CVSS Published ↓ Description
CVE-2026-88365 NONE — 2026-09-24 minimp3 commit ea99364f contains an integer overflow vulnerability in mp3dec_skip_id3v1() when parsing the APEv2 tag-size field.
CVE-2026-88362 NONE — 2026-09-24 MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_isindex() in jsrun.c. A specially crafted JavaScript input containing an excessively large nume…
CVE-2026-88361 NONE — 2026-09-24 SumatraPDF 3.6.1 contains an integer overflow vulnerability in EngineMupdf::BuildPageLabelRec() when parsing PDF PageLabels /Nums entries.
CVE-2026-88358 NONE — 2026-09-24 simdjson 4.6.1 contains a one-byte out-of-bounds read vulnerability in dom::parser::parse_unpadded(). A specially crafted truncated JSON document whose final structural tok…
CVE-2026-88357 HIGH 7.5 2026-09-24 nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. Specially crafted network input can cause byte-buffer addresses at odd o…
CVE-2026-88355 NONE — 2026-09-24 An incorrect buffer size calculation vulnerability exists in tinyexpr commit 4a7456e in new_expr(). For arity-0 expression nodes, including constants, variables, and zero-a…
CVE-2026-79761 MEDIUM Patched 6.6 2026-09-24 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0 until 2.5.1, the Termix SSH key deployment flow der…
CVE-2026-79760 MEDIUM Patched 6.4 2026-09-24 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0 until 2.5.1, Termix allows authenticated users to c…
CVE-2026-79759 MEDIUM Patched 4.3 2026-09-24 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0 until 2.5.1, the POST /credentials/:id/deploy-to-ho…
CVE-2026-79758 MEDIUM Patched 5.4 2026-09-24 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.8.0 until 2.5.1, authenticated Termix users can access …
CVE-2026-77581 HIGH Patched 8.6 2026-09-24 BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, the certificate and timestamp CORS proxy in cloudflare/cors-proxy-worker.js uses isPrivat…
CVE-2026-76907 MEDIUM Patched 6.5 2026-09-24 LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 4.8.2 until 5.4.0, GET /api/v1.0/documents/search/ accepts sequential seven-digit document…
CVE-2026-75907 HIGH 7.5 2026-09-24 The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID stored on an NTAG212 NFC chip. A UID is a manufacture…
CVE-2026-67233 NONE Patched — 2026-09-24 RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The shovel management resource's is_authorized/2 delegates to rab…
CVE-2026-63630 LOW Patched 3.4 2026-09-24 BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, deserializeWorkflow() accepts the Timestamp node's tsaUrl control from imported JSON with…
CVE-2026-63203 HIGH Patched 7.6 2026-09-24 Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API handlers in packages/core/src/routes/account/third-part…
CVE-2026-56739 NONE Patched — 2026-09-24 Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.43.0, Logto fetches administrator-controlled outbound destinations without validating …
CVE-2026-56737 HIGH Patched 8.1 2026-09-24 phpMyFAQ is an open source FAQ web application. Versions 3.2.0 through 4.1.5 contain an authentication bypass in its public two-factor authentication verification flow: an …
CVE-2025-32000 MEDIUM 4.3 2026-09-24 HCL Sametime is vulnerable to insufficient input sanitization. The application did not appropriately sanitize user input. When user input is implicitly or explicitly truste…
CVE-2026-97404 NONE Patched — 2026-09-24 In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticated remote att…
CVE-2026-97362 HIGH 7.5 2026-09-24 HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by s…
CVE-2026-97224 MEDIUM 4.3 2026-09-24 A vulnerability was detected in Excalidraw up to 0.18.1. The impacted element is an unknown function of the file packages/excalidraw/data/restore.ts of the component Import…
CVE-2026-90959 HIGH 8.1 2026-09-24 A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a l…
CVE-2026-90481 NONE Patched — 2026-09-24 In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel.
CVE-2026-88351 NONE — 2026-09-24 An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specially crafted MessagePack array32 or map32 object with…