Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 2,372 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-52130 | HIGH | Patched | 7.5 | 2026-09-01 | llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to-grammar.cpp, resulting in a denial of service. |
| CVE-2026-52131 | HIGH | Patched | 7.5 | 2026-09-01 | llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function. |
| CVE-2026-52132 | HIGH | Patched | 7.5 | 2026-09-01 | llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a negative … |
| CVE-2026-52295 | MEDIUM | 6.2 | 2026-09-01 | Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows an attacker to cause a denial of service via the libavformat/iamf_writer.c component | |
| CVE-2026-52691 | NONE | — | 2026-09-04 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module. … | |
| CVE-2026-52762 | NONE | Patched | — | 2026-09-05 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) vulnerability in the semantic templat… |
| CVE-2026-52763 | MEDIUM | Patched | 6.5 | 2026-09-05 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the recentchanges action (actions/recentchanges.php) accepts a period argument from two disjoint parameter … |
| CVE-2026-52766 | CRITICAL | Patched | 9.1 | 2026-09-05 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array fro… |
| CVE-2026-52767 | HIGH | Patched | 8.2 | 2026-09-05 | YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() wit… |
| CVE-2026-52769 | HIGH | Patched | 8.3 | 2026-09-05 | YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route - exposed publicly with acl:"public" - a… |
| CVE-2026-52770 | HIGH | Patched | 7.5 | 2026-09-05 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthenticated SQL injection in numeric query … |
| CVE-2026-52771 | HIGH | Patched | 8.3 | 2026-09-05 | YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a page tag retrieved from the database into a … |
| CVE-2026-52772 | MEDIUM | Patched | 5.5 | 2026-09-05 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field.label / field.hint in attribute and label-body… |
| CVE-2026-52773 | MEDIUM | Patched | 6.1 | 2026-09-05 | YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view reflects the time GET parameter into a hidden HTML inp… |
| CVE-2026-52774 | MEDIUM | Patched | 6.1 | 2026-09-05 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki's Bazar widget handler reflects the id GET parameter into HTML attributes using strip_tags() only. … |
| CVE-2026-52775 | HIGH | Patched | 8.8 | 2026-09-05 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::de… |
| CVE-2026-52777 | NONE | Patched | — | 2026-09-05 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This iss… |
| CVE-2026-52831 | HIGH | Patched | 8.0 | 2026-09-02 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron tr… |
| CVE-2026-52832 | MEDIUM | Patched | 4.9 | 2026-09-02 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio Dashboard exposes POST /api/functions without authentication by… |
| CVE-2026-52833 | HIGH | Patched | 8.0 | 2026-09-02 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function bu… |
| CVE-2026-53600 | NONE | Patched | — | 2026-09-02 | async-tar is a tar archive reading/writing library for async Rust. Prior to version 0.6.1, async-tar mis-applies a buffered PAX size extension to an intermediary extension … |
| CVE-2026-53602 | NONE | Patched | — | 2026-09-04 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host that should no longer be trusted obt… |
| CVE-2026-53603 | NONE | Patched | — | 2026-09-04 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table… |
| CVE-2026-53604 | NONE | Patched | — | 2026-09-04 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, the web handler renderMobileBundle passes the real *pki.CAResolver directly in… |
| CVE-2026-53611 | CRITICAL | Patched | 9.8 | 2026-09-02 | Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute /… |