Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 426–450 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-52130 HIGH Patched 7.5 2026-09-01 llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to-grammar.cpp, resulting in a denial of service.
CVE-2026-52131 HIGH Patched 7.5 2026-09-01 llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function.
CVE-2026-52132 HIGH Patched 7.5 2026-09-01 llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a negative …
CVE-2026-52295 MEDIUM 6.2 2026-09-01 Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows an attacker to cause a denial of service via the libavformat/iamf_writer.c component
CVE-2026-52691 NONE — 2026-09-04 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module. …
CVE-2026-52762 NONE Patched — 2026-09-05 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) vulnerability in the semantic templat…
CVE-2026-52763 MEDIUM Patched 6.5 2026-09-05 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the recentchanges action (actions/recentchanges.php) accepts a period argument from two disjoint parameter …
CVE-2026-52766 CRITICAL Patched 9.1 2026-09-05 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array fro…
CVE-2026-52767 HIGH Patched 8.2 2026-09-05 YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() wit…
CVE-2026-52769 HIGH Patched 8.3 2026-09-05 YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route - exposed publicly with acl:"public" - a…
CVE-2026-52770 HIGH Patched 7.5 2026-09-05 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthenticated SQL injection in numeric query …
CVE-2026-52771 HIGH Patched 8.3 2026-09-05 YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a page tag retrieved from the database into a …
CVE-2026-52772 MEDIUM Patched 5.5 2026-09-05 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field.label / field.hint in attribute and label-body…
CVE-2026-52773 MEDIUM Patched 6.1 2026-09-05 YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view reflects the time GET parameter into a hidden HTML inp…
CVE-2026-52774 MEDIUM Patched 6.1 2026-09-05 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki's Bazar widget handler reflects the id GET parameter into HTML attributes using strip_tags() only. …
CVE-2026-52775 HIGH Patched 8.8 2026-09-05 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::de…
CVE-2026-52777 NONE Patched — 2026-09-05 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This iss…
CVE-2026-52831 HIGH Patched 8.0 2026-09-02 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron tr…
CVE-2026-52832 MEDIUM Patched 4.9 2026-09-02 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio Dashboard exposes POST /api/functions without authentication by…
CVE-2026-52833 HIGH Patched 8.0 2026-09-02 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function bu…
CVE-2026-53600 NONE Patched — 2026-09-02 async-tar is a tar archive reading/writing library for async Rust. Prior to version 0.6.1, async-tar mis-applies a buffered PAX size extension to an intermediary extension …
CVE-2026-53602 NONE Patched — 2026-09-04 nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host that should no longer be trusted obt…
CVE-2026-53603 NONE Patched — 2026-09-04 nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table…
CVE-2026-53604 NONE Patched — 2026-09-04 nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, the web handler renderMobileBundle passes the real *pki.CAResolver directly in…
CVE-2026-53611 CRITICAL Patched 9.8 2026-09-02 Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute /…