Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,281 CVEs

CVEs (2,281, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 426–450 of 2,281 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-23585 NONE — 2026-09-02 Rejected reason: Withdrawn by requester.
CVE-2026-23586 NONE — 2026-09-02 Rejected reason: Withdrawn by requester.
CVE-2026-23587 NONE — 2026-09-02 Rejected reason: Withdrawn by requester.
CVE-2026-23588 NONE — 2026-09-02 Rejected reason: Withdrawn by requester.
CVE-2026-23589 NONE — 2026-09-02 Rejected reason: Withdrawn by requester.
CVE-2026-23590 NONE — 2026-09-02 Rejected reason: Withdrawn by requester.
CVE-2026-23591 NONE — 2026-09-02 Rejected reason: Withdrawn by requester.
CVE-2026-23583 NONE — 2026-09-02 Rejected reason: Withdrawn by requester.
CVE-2026-19754 NONE — 2026-09-02 Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify formula fields can provid…
CVE-2026-84481 NONE — 2026-09-01 WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to…
CVE-2026-76851 NONE Patched — 2026-09-01 A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance. Insufficient network isola…
CVE-2026-19118 NONE Patched — 2026-09-01 A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticat…
CVE-2026-18730 NONE Patched — 2026-09-01 A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send craft…
CVE-2026-84361 NONE Patched — 2026-09-01 Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted co…
CVE-2026-84310 NONE Patched — 2026-09-01 pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes…
CVE-2026-84311 NONE Patched — 2026-09-01 pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.ext…
CVE-2026-84309 NONE Patched — 2026-09-01 pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py T…
CVE-2026-77221 NONE — 2026-09-01 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-77222 NONE — 2026-09-01 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-77223 NONE — 2026-09-01 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-84303 NONE Patched — 2026-09-01 gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names…
CVE-2026-84304 NONE Patched — 2026-09-01 gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBu…
CVE-2026-84305 NONE Patched — 2026-09-01 sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse.format(sql, reindent=True) and sqlformat --reindent route attacker-controlled parenthesi…
CVE-2026-52023 NONE — 2026-09-01 An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_p…
CVE-2024-7952 NONE — 2026-09-01 A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be reached without authenticatio…