Search
140,606 CVEs · High severity
CVEs (140,606, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 140,606 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2021-38489 | HIGH | 8.2 | 2026-09-03 | HDD password plaintext is stored in a UEFI variable. | |
| CVE-2026-84851 | HIGH | Patched | 7.5 | 2026-09-03 | An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call… |
| CVE-2026-84394 | HIGH | Patched | 7.5 | 2026-09-03 | fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but does not end w… |
| CVE-2026-84292 | HIGH | Patched | 7.5 | 2026-09-02 | fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concaten… |
| CVE-2026-82524 | HIGH | Patched | 7.2 | 2026-09-02 | UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP files through the TinyMCE image upl… |
| CVE-2026-78662 | HIGH | Patched | 7.5 | 2026-09-02 | Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking th… |
| CVE-2026-56855 | HIGH | Patched | 7.5 | 2026-09-02 | Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channe… |
| CVE-2023-20577 | HIGH | 7.4 | 2026-09-02 | A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution. | |
| CVE-2023-20576 | HIGH | 7.7 | 2026-09-02 | Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation. | |
| CVE-2026-84841 | HIGH | 7.3 | 2026-09-02 | A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enforcement of se… | |
| CVE-2026-84382 | HIGH | Patched | 7.5 | 2026-09-02 | HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or … |
| CVE-2026-84381 | HIGH | Patched | 8.1 | 2026-09-02 | HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore… |
| CVE-2026-49832 | HIGH | Patched | 8.0 | 2026-09-02 | DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before … |
| CVE-2026-82404 | HIGH | Patched | 8.3 | 2026-09-02 | TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype … |
| CVE-2026-79755 | HIGH | Patched | 8.0 | 2026-09-02 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, on the Nuclio local Docker platform, the function namespace is interpo… |
| CVE-2026-53635 | HIGH | 7.6 | 2026-09-02 | Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 59bb6d6, the view function set_course_mode_price() at lms/djangoapps/i… | |
| CVE-2026-52833 | HIGH | Patched | 8.0 | 2026-09-02 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function bu… |
| CVE-2026-52831 | HIGH | Patched | 8.0 | 2026-09-02 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron tr… |
| CVE-2026-45730 | HIGH | Patched | 8.3 | 2026-09-02 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0, there is a vulnerability in Nuclio Dashboard's project management API,… |
| CVE-2026-20281 | HIGH | 7.5 | 2026-09-02 | A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) So… | |
| CVE-2026-20280 | HIGH | 8.8 | 2026-09-02 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal secu… | |
| CVE-2026-20278 | HIGH | 8.8 | 2026-09-02 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … | |
| CVE-2026-20277 | HIGH | 8.2 | 2026-09-02 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … | |
| CVE-2026-20276 | HIGH | 8.6 | 2026-09-02 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … | |
| CVE-2026-20275 | HIGH | 8.8 | 2026-09-02 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … |