Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 2,372 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86119 | HIGH | 8.6 | 2026-09-05 | Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGI… | |
| CVE-2026-82304 | HIGH | Patched | 8.6 | 2026-09-05 | The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthe… |
| CVE-2026-50553 | NONE | Patched | — | 2026-09-04 | Note Mark is an open-source note-taking application. Prior to version 0.19.5, Note Mark validates book and note slug values with the OpenAPI/huma tag pattern:"[a-z0-9-]+". … |
| CVE-2026-19305 | HIGH | 8.6 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery. | |
| CVE-2026-85620 | HIGH | 8.6 | 2026-09-04 | Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. Attackers can e… | |
| CVE-2026-85614 | HIGH | Patched | 8.6 | 2026-09-04 | OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled … |
| CVE-2026-85546 | NONE | — | 2026-09-04 | MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions sh… | |
| CVE-2026-63219 | HIGH | Patched | 8.6 | 2026-09-03 | GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file up… |
| CVE-2026-85237 | NONE | — | 2026-09-03 | A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The … | |
| CVE-2026-84830 | NONE | Patched | — | 2026-09-03 | SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges. |
| CVE-2026-84832 | NONE | Patched | — | 2026-09-03 | SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privi… |
| CVE-2026-76176 | NONE | — | 2026-09-03 | SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the selected_gr… | |
| CVE-2026-76175 | NONE | — | 2026-09-03 | SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list endpoint. Input provided by an authenticated user with operator privileg… | |
| CVE-2026-84452 | NONE | Patched | — | 2026-09-02 | Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py … |
| CVE-2026-20276 | HIGH | 8.6 | 2026-09-02 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … | |
| CVE-2024-35585 | HIGH | Patched | 8.6 | 2026-09-02 | Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication. |
| CVE-2026-19754 | NONE | — | 2026-09-02 | Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify formula fields can provid… | |
| CVE-2026-84700 | HIGH | 8.6 | 2026-09-02 | PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is use… | |
| CVE-2026-73706 | HIGH | Patched | 8.6 | 2026-09-01 | A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to obtain limited system information and to change the state of … |
| CVE-2025-12768 | NONE | — | 2026-09-01 | A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code exe… | |
| CVE-2026-84194 | NONE | Patched | — | 2026-09-01 | LibreNMS versions >= 23.10.0 and < 26.2.0 (fixed in 26.4.0) contain an authenticated OS command injection vulnerability in libvirt discovery. When libvirt support is enable… |
| CVE-2026-77091 | NONE | Patched | — | 2026-09-08 | DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and I… |
| CVE-2026-74860 | HIGH | 8.5 | 2026-09-08 | A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Docu… | |
| CVE-2026-76958 | HIGH | 8.5 | 2026-09-08 | SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could sub… | |
| CVE-2026-86492 | HIGH | Patched | 8.5 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens |