Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

140,606 CVEs · High severity

CVEs (140,606, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 401–425 of 140,606 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2021-38489 HIGH 8.2 2026-09-03 HDD password plaintext is stored in a UEFI variable.
CVE-2026-84851 HIGH Patched 7.5 2026-09-03 An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call…
CVE-2026-84394 HIGH Patched 7.5 2026-09-03 fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but does not end w…
CVE-2026-84292 HIGH Patched 7.5 2026-09-02 fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concaten…
CVE-2026-82524 HIGH Patched 7.2 2026-09-02 UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP files through the TinyMCE image upl…
CVE-2026-78662 HIGH Patched 7.5 2026-09-02 Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking th…
CVE-2026-56855 HIGH Patched 7.5 2026-09-02 Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channe…
CVE-2023-20577 HIGH 7.4 2026-09-02 A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution.
CVE-2023-20576 HIGH 7.7 2026-09-02 Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation.
CVE-2026-84841 HIGH 7.3 2026-09-02 A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enforcement of se…
CVE-2026-84382 HIGH Patched 7.5 2026-09-02 HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or …
CVE-2026-84381 HIGH Patched 8.1 2026-09-02 HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore…
CVE-2026-49832 HIGH Patched 8.0 2026-09-02 DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before …
CVE-2026-82404 HIGH Patched 8.3 2026-09-02 TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype …
CVE-2026-79755 HIGH Patched 8.0 2026-09-02 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, on the Nuclio local Docker platform, the function namespace is interpo…
CVE-2026-53635 HIGH 7.6 2026-09-02 Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 59bb6d6, the view function set_course_mode_price() at lms/djangoapps/i…
CVE-2026-52833 HIGH Patched 8.0 2026-09-02 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function bu…
CVE-2026-52831 HIGH Patched 8.0 2026-09-02 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron tr…
CVE-2026-45730 HIGH Patched 8.3 2026-09-02 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0, there is a vulnerability in Nuclio Dashboard's project management API,…
CVE-2026-20281 HIGH 7.5 2026-09-02 A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) So…
CVE-2026-20280 HIGH 8.8 2026-09-02 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal secu…
CVE-2026-20278 HIGH 8.8 2026-09-02 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security …
CVE-2026-20277 HIGH 8.2 2026-09-02 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security …
CVE-2026-20276 HIGH 8.6 2026-09-02 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security …
CVE-2026-20275 HIGH 8.8 2026-09-02 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security …