Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 2,372 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85392 | MEDIUM | 4.3 | 2026-09-03 | Peppermint through 0.5.5 contains an authorization bypass vulnerability in the GET /api/v1/auth/user/:id/logout endpoint that allows authenticated attackers to delete sessi… | |
| CVE-2026-82298 | MEDIUM | 4.3 | 2026-09-03 | Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). | |
| CVE-2026-78593 | MEDIUM | 4.3 | 2026-09-03 | An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-con… | |
| CVE-2026-78595 | MEDIUM | 4.3 | 2026-09-03 | Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privi… | |
| CVE-2026-78596 | MEDIUM | 4.3 | 2026-09-03 | Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via P… | |
| CVE-2026-82023 | MEDIUM | Patched | 4.3 | 2026-09-03 | LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answ… |
| CVE-2026-84967 | MEDIUM | 4.3 | 2026-09-03 | A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line th… | |
| CVE-2026-85210 | MEDIUM | 4.3 | 2026-09-03 | Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. A… | |
| CVE-2026-85161 | MEDIUM | 4.3 | 2026-09-03 | AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster.php that lacks forbidIfNotPost or forbidIfInvalidToken checks. Attackers… | |
| CVE-2026-85100 | MEDIUM | 4.3 | 2026-09-03 | A vulnerability was detected in 2FastLabs agent-squad up to 1.1.4. Affected by this vulnerability is the function AgentSquad.routeRequest of the file agent-squad/typescript… | |
| CVE-2026-85107 | MEDIUM | 4.3 | 2026-09-03 | A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability affects the function resourceBufferFromUrl of the file apps/desktop/electron/main.ts of th… | |
| CVE-2026-85021 | MEDIUM | 4.3 | 2026-09-03 | A vulnerability was determined in langgenius dify 1.13.0. Affected is the function router.replace of the file web/app/(shareLayout)/components/splash.tsx of the component S… | |
| CVE-2026-84885 | MEDIUM | 4.3 | 2026-09-03 | A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This impacts an unknown function of the file code_agent.py of the component CodeAgent. Such manipulation l… | |
| CVE-2026-84887 | MEDIUM | 4.3 | 2026-09-03 | A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affected by this issue is some unknown functionality of the file grounding.py of the component Model-gener… | |
| CVE-2026-84888 | MEDIUM | 4.3 | 2026-09-03 | A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. This vulnerability affects the function shell_exec of the file crates/openfang-runtime/src/tool_runner.r… | |
| CVE-2026-84833 | MEDIUM | 4.3 | 2026-09-02 | A vulnerability was found in ntegrals openbrowser up to 067fc45d649baa961750da8e2f4a75d87c5c75c8. Affected by this vulnerability is an unknown functionality of the file pac… | |
| CVE-2026-84676 | MEDIUM | 4.3 | 2026-09-02 | Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users … | |
| CVE-2026-84655 | MEDIUM | 4.3 | 2026-09-02 | Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to con… | |
| CVE-2026-84656 | MEDIUM | 4.3 | 2026-09-02 | A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter name… | |
| CVE-2026-84658 | MEDIUM | 4.3 | 2026-09-02 | Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowi… | |
| CVE-2026-84659 | MEDIUM | 4.3 | 2026-09-02 | Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in… | |
| CVE-2026-84662 | MEDIUM | 4.3 | 2026-09-02 | Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler data binding, allowing attackers to connect to an attacker-speci… | |
| CVE-2026-84646 | MEDIUM | 4.3 | 2026-09-02 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Rea… | |
| CVE-2026-82293 | MEDIUM | 4.3 | 2026-09-02 | Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control … | |
| CVE-2026-78584 | MEDIUM | Patched | 4.3 | 2026-09-02 | Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated use… |