Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

163,503 CVEs · Medium severity

CVEs (163,503, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 401–425 of 163,503 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-85241 MEDIUM 6.3 2026-09-03 A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of the file cmd/api/src/api/registration/v2.go of the com…
CVE-2026-9745 MEDIUM 6.5 2026-09-03 IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This om…
CVE-2026-9744 MEDIUM 5.3 2026-09-03 IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitiv…
CVE-2026-9736 MEDIUM 5.3 2026-09-03 IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements w…
CVE-2026-9036 MEDIUM 5.9 2026-09-03 IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitiv…
CVE-2026-84185 MEDIUM 5.9 2026-09-03 A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifi…
CVE-2026-82521 MEDIUM Patched 5.3 2026-09-03 parsedmarc 9.0.6 before 11.0.1 writes forensic report sample files using an output path derived from the email subject. When the subject consists entirely of path traversal…
CVE-2026-71429 MEDIUM Patched 6.2 2026-09-03 stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.5.0, the path filters pick, ignore, filter, an…
CVE-2026-85044 MEDIUM 6.5 2026-09-03 Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy…
CVE-2026-19795 MEDIUM 6.2 2026-09-03 Qiskit could allow a local attacker to cause a denial of service due to a stack overflow during deserialization of QPY payloads. A malicious QPY payload can trigger a segme…
CVE-2026-85392 MEDIUM 4.3 2026-09-03 Peppermint through 0.5.5 contains an authorization bypass vulnerability in the GET /api/v1/auth/user/:id/logout endpoint that allows authenticated attackers to delete sessi…
CVE-2026-85389 MEDIUM Patched 6.5 2026-09-03 Worklenz before 3.0.0 fails to verify task ownership by organization when resolving task-scoped API endpoints, allowing authenticated users to access another tenant's task …
CVE-2026-85205 MEDIUM 6.3 2026-09-03 A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addwishlist of the file /customer/controller.php?action=…
CVE-2026-82299 MEDIUM 6.5 2026-09-03 Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
CVE-2026-82298 MEDIUM 4.3 2026-09-03 Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
CVE-2026-78596 MEDIUM 4.3 2026-09-03 Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via P…
CVE-2026-78595 MEDIUM 4.3 2026-09-03 Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privi…
CVE-2026-78593 MEDIUM 4.3 2026-09-03 An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-con…
CVE-2026-49455 MEDIUM Patched 6.5 2026-09-03 Waku is the minimal React framework. Prior to version 1.0.0-beta.1, Waku's RSC request dispatcher invokes server actions without validating the request's Origin (or Sec-Fet…
CVE-2026-84968 MEDIUM 5.3 2026-09-03 An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount…
CVE-2026-82024 MEDIUM Patched 5.4 2026-09-03 LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers with the Instructor role to inject persist…
CVE-2026-82023 MEDIUM Patched 4.3 2026-09-03 LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answ…
CVE-2026-85309 MEDIUM 5.3 2026-09-03 Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ult…
CVE-2026-85308 MEDIUM 5.3 2026-09-03 Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This …
CVE-2026-85307 MEDIUM Patched 5.3 2026-09-03 Insertion of Sensitive Information Into Sent Data vulnerability in Kevin Pirnie KP Agent Ready allows Retrieve Embedded Sensitive Data. This issue affects KP Agent Ready: …