Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

140,640 CVEs · High severity

CVEs (140,640, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 426–450 of 140,640 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-80732 HIGH 7.8 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: ata: pata_sl82c105: fix bridge revision use-after-free pci_get_slot() returns a referenced PCI device.…
CVE-2026-79679 HIGH Patched 8.7 2026-09-03 Use of Weak Credentials vulnerability in B&R Industrial Automation GmbH mapp Audit used in mapp Services. This issue affects mapp Audit used in mapp Services: before 6.8.0.
CVE-2026-80465 HIGH 8.7 2026-09-03 A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (&hellip;
CVE-2026-76642 HIGH 7.8 2026-09-03 util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged oper&hellip;
CVE-2026-73600 HIGH 7.8 2026-09-03 Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack buffer overflow vulnerability in file-level restore agent. A high privileged remote attacker co&hellip;
CVE-2026-71220 HIGH 7.0 2026-09-03 A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds ch&hellip;
CVE-2026-71221 HIGH 7.0 2026-09-03 A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking&hellip;
CVE-2021-38489 HIGH 8.2 2026-09-03 HDD password plaintext is stored in a UEFI variable.
CVE-2026-84851 HIGH Patched 7.5 2026-09-03 An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call&hellip;
CVE-2026-84394 HIGH Patched 7.5 2026-09-03 fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but does not end w&hellip;
CVE-2026-82524 HIGH Patched 7.2 2026-09-02 UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP files through the TinyMCE image upl&hellip;
CVE-2026-84292 HIGH Patched 7.5 2026-09-02 fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concaten&hellip;
CVE-2026-78662 HIGH Patched 7.5 2026-09-02 Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking th&hellip;
CVE-2026-56855 HIGH Patched 7.5 2026-09-02 Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channe&hellip;
CVE-2023-20577 HIGH 7.4 2026-09-02 A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution.
CVE-2023-20576 HIGH 7.7 2026-09-02 Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation.
CVE-2026-84841 HIGH 7.3 2026-09-02 A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enforcement of se&hellip;
CVE-2026-84381 HIGH Patched 8.1 2026-09-02 HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore&hellip;
CVE-2026-84382 HIGH Patched 7.5 2026-09-02 HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or &hellip;
CVE-2026-49832 HIGH Patched 8.0 2026-09-02 DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before &hellip;
CVE-2026-82404 HIGH Patched 8.3 2026-09-02 TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype &hellip;
CVE-2026-79755 HIGH Patched 8.0 2026-09-02 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, on the Nuclio local Docker platform, the function namespace is interpo&hellip;
CVE-2026-52831 HIGH Patched 8.0 2026-09-02 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron tr&hellip;
CVE-2026-52833 HIGH Patched 8.0 2026-09-02 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function bu&hellip;
CVE-2026-53635 HIGH 7.6 2026-09-02 Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 59bb6d6, the view function set_course_mode_price() at lms/djangoapps/i&hellip;