Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 426–450 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-86119 HIGH 8.6 2026-09-05 Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGI…
CVE-2026-82304 HIGH Patched 8.6 2026-09-05 The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthe…
CVE-2026-50553 NONE Patched — 2026-09-04 Note Mark is an open-source note-taking application. Prior to version 0.19.5, Note Mark validates book and note slug values with the OpenAPI/huma tag pattern:"[a-z0-9-]+". …
CVE-2026-19305 HIGH 8.6 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.
CVE-2026-85620 HIGH 8.6 2026-09-04 Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. Attackers can e…
CVE-2026-85614 HIGH Patched 8.6 2026-09-04 OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled …
CVE-2026-85546 NONE — 2026-09-04 MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions sh…
CVE-2026-63219 HIGH Patched 8.6 2026-09-03 GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file up…
CVE-2026-85237 NONE — 2026-09-03 A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The …
CVE-2026-84830 NONE Patched — 2026-09-03 SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges.
CVE-2026-84832 NONE Patched — 2026-09-03 SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privi…
CVE-2026-76176 NONE — 2026-09-03 SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the selected_gr…
CVE-2026-76175 NONE — 2026-09-03 SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list endpoint. Input provided by an authenticated user with operator privileg…
CVE-2026-84452 NONE Patched — 2026-09-02 Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py …
CVE-2026-20276 HIGH 8.6 2026-09-02 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security …
CVE-2024-35585 HIGH Patched 8.6 2026-09-02 Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.
CVE-2026-19754 NONE — 2026-09-02 Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify formula fields can provid…
CVE-2026-84700 HIGH 8.6 2026-09-02 PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is use…
CVE-2026-73706 HIGH Patched 8.6 2026-09-01 A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to obtain limited system information and to change the state of …
CVE-2025-12768 NONE — 2026-09-01 A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code exe…
CVE-2026-84194 NONE Patched &mdash; 2026-09-01 LibreNMS versions >= 23.10.0 and < 26.2.0 (fixed in 26.4.0) contain an authenticated OS command injection vulnerability in libvirt discovery. When libvirt support is enable&hellip;
CVE-2026-77091 NONE Patched &mdash; 2026-09-08 DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and I&hellip;
CVE-2026-74860 HIGH 8.5 2026-09-08 A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Docu&hellip;
CVE-2026-76958 HIGH 8.5 2026-09-08 SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could sub&hellip;
CVE-2026-86492 HIGH Patched 8.5 2026-09-07 In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens