Search
13,088 CVEs
CVEs (13,088, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 13,088 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-66049 | NONE | — | 2026-09-03 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-84452 | NONE | Patched | — | 2026-09-02 | Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py … |
| CVE-2026-77125 | NONE | — | 2026-09-02 | A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did not correctly enforce the intended authorizatio… | |
| CVE-2026-77123 | NONE | Patched | — | 2026-09-02 | Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding the nexus:capabilities:read privilege can retrie… |
| CVE-2026-77124 | NONE | — | 2026-09-02 | In affected versions of Nexus Repository 3, the script execution endpoint (POST /service/rest/v1/script/{name}/run) did not verify whether script execution had been adminis… | |
| CVE-2026-77121 | NONE | — | 2026-09-02 | A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts … | |
| CVE-2026-77122 | NONE | — | 2026-09-02 | An authorization flaw in the REST API repository details endpoint (GET /service/rest/v1/repositories/{repositoryName}) in Sonatype Nexus Repository 3 allowed an account hol… | |
| CVE-2026-53670 | NONE | Patched | — | 2026-09-02 | PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, in the Prevail eBPF verifier, EbpfTransformer::add() silently … |
| CVE-2026-53671 | NONE | Patched | — | 2026-09-02 | PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the abstract transformer in prevail treats writes through a T_… |
| CVE-2026-53706 | NONE | Patched | — | 2026-09-02 | PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the prevail eBPF verifier accepts ALU32 ADD and SUB instructio… |
| CVE-2026-49249 | NONE | Patched | — | 2026-09-02 | Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.10.0, Boruta… |
| CVE-2026-79756 | NONE | Patched | — | 2026-09-02 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, the fix for unauthenticated OS command injection in the nuclio dashboa… |
| CVE-2026-84376 | NONE | Patched | — | 2026-09-02 | Astro is a web framework for content-driven websites. Prior to 7.2.4, Astro stripped a configured non-root base path from request pathnames using a string-prefix check with… |
| CVE-2026-79754 | NONE | Patched | — | 2026-09-02 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. From version 1.6.19 to before version 1.17.2, Nuclio's Dashboard build pipeline does not saniti… |
| CVE-2026-53600 | NONE | Patched | — | 2026-09-02 | async-tar is a tar archive reading/writing library for async Rust. Prior to version 0.6.1, async-tar mis-applies a buffered PAX size extension to an intermediary extension … |
| CVE-2026-82955 | NONE | — | 2026-09-02 | In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component had the disable_… | |
| CVE-2026-79989 | NONE | — | 2026-09-02 | The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the… | |
| CVE-2026-79990 | NONE | — | 2026-09-02 | Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the… | |
| CVE-2026-79991 | NONE | — | 2026-09-02 | Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the… | |
| CVE-2024-7956 | NONE | — | 2026-09-02 | A vulnerability exists in the affected products that allows a threat actor to gain access to user’s projects. To exploit this vulnerability the threat actor must have basic… | |
| CVE-2025-13398 | NONE | — | 2026-09-02 | Rejected reason: This CVE ID is a duplicate of CVE-2025-13542 and was never published. Both IDs were assigned to the same unauthenticated privilege escalation vulnerability… | |
| CVE-2026-82958 | NONE | — | 2026-09-02 | In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service builds a CreateThing command by substituting placeholder values… | |
| CVE-2026-84175 | NONE | — | 2026-09-02 | In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over HTTP from URLs supplied by API users in the definition field of a … | |
| CVE-2026-23584 | NONE | — | 2026-09-02 | Rejected reason: Withdrawn by requester. | |
| CVE-2026-23585 | NONE | — | 2026-09-02 | Rejected reason: Withdrawn by requester. |