Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 426–450 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-85392 MEDIUM 4.3 2026-09-03 Peppermint through 0.5.5 contains an authorization bypass vulnerability in the GET /api/v1/auth/user/:id/logout endpoint that allows authenticated attackers to delete sessi…
CVE-2026-82298 MEDIUM 4.3 2026-09-03 Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
CVE-2026-78593 MEDIUM 4.3 2026-09-03 An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-con…
CVE-2026-78595 MEDIUM 4.3 2026-09-03 Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privi…
CVE-2026-78596 MEDIUM 4.3 2026-09-03 Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via P…
CVE-2026-82023 MEDIUM Patched 4.3 2026-09-03 LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answ…
CVE-2026-84967 MEDIUM 4.3 2026-09-03 A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line th…
CVE-2026-85210 MEDIUM 4.3 2026-09-03 Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. A…
CVE-2026-85161 MEDIUM 4.3 2026-09-03 AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster.php that lacks forbidIfNotPost or forbidIfInvalidToken checks. Attackers…
CVE-2026-85100 MEDIUM 4.3 2026-09-03 A vulnerability was detected in 2FastLabs agent-squad up to 1.1.4. Affected by this vulnerability is the function AgentSquad.routeRequest of the file agent-squad/typescript…
CVE-2026-85107 MEDIUM 4.3 2026-09-03 A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability affects the function resourceBufferFromUrl of the file apps/desktop/electron/main.ts of th…
CVE-2026-85021 MEDIUM 4.3 2026-09-03 A vulnerability was determined in langgenius dify 1.13.0. Affected is the function router.replace of the file web/app/(shareLayout)/components/splash.tsx of the component S…
CVE-2026-84885 MEDIUM 4.3 2026-09-03 A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This impacts an unknown function of the file code_agent.py of the component CodeAgent. Such manipulation l…
CVE-2026-84887 MEDIUM 4.3 2026-09-03 A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affected by this issue is some unknown functionality of the file grounding.py of the component Model-gener…
CVE-2026-84888 MEDIUM 4.3 2026-09-03 A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. This vulnerability affects the function shell_exec of the file crates/openfang-runtime/src/tool_runner.r…
CVE-2026-84833 MEDIUM 4.3 2026-09-02 A vulnerability was found in ntegrals openbrowser up to 067fc45d649baa961750da8e2f4a75d87c5c75c8. Affected by this vulnerability is an unknown functionality of the file pac…
CVE-2026-84676 MEDIUM 4.3 2026-09-02 Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users …
CVE-2026-84655 MEDIUM 4.3 2026-09-02 Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to con…
CVE-2026-84656 MEDIUM 4.3 2026-09-02 A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter name…
CVE-2026-84658 MEDIUM 4.3 2026-09-02 Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowi…
CVE-2026-84659 MEDIUM 4.3 2026-09-02 Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in…
CVE-2026-84662 MEDIUM 4.3 2026-09-02 Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler data binding, allowing attackers to connect to an attacker-speci…
CVE-2026-84646 MEDIUM 4.3 2026-09-02 In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Rea…
CVE-2026-82293 MEDIUM 4.3 2026-09-02 Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control …
CVE-2026-78584 MEDIUM Patched 4.3 2026-09-02 Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated use…