Search
11,582 CVEs · High severity
CVEs (11,582, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 11,582 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-80731 | HIGH | 7.8 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header dev_validate_header() reads dev->hard_he… | |
| CVE-2026-80465 | HIGH | 8.7 | 2026-09-03 | A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (… | |
| CVE-2026-79679 | HIGH | Patched | 8.7 | 2026-09-03 | Use of Weak Credentials vulnerability in B&R Industrial Automation GmbH mapp Audit used in mapp Services. This issue affects mapp Audit used in mapp Services: before 6.8.0. |
| CVE-2026-76642 | HIGH | 7.8 | 2026-09-03 | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged oper… | |
| CVE-2026-73600 | HIGH | 7.8 | 2026-09-03 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack buffer overflow vulnerability in file-level restore agent. A high privileged remote attacker co… | |
| CVE-2026-71221 | HIGH | 7.0 | 2026-09-03 | A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking… | |
| CVE-2026-71220 | HIGH | 7.0 | 2026-09-03 | A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds ch… | |
| CVE-2021-38489 | HIGH | 8.2 | 2026-09-03 | HDD password plaintext is stored in a UEFI variable. | |
| CVE-2026-84851 | HIGH | Patched | 7.5 | 2026-09-03 | An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call… |
| CVE-2026-84394 | HIGH | Patched | 7.5 | 2026-09-03 | fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but does not end w… |
| CVE-2026-84292 | HIGH | Patched | 7.5 | 2026-09-02 | fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concaten… |
| CVE-2026-82524 | HIGH | Patched | 7.2 | 2026-09-02 | UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP files through the TinyMCE image upl… |
| CVE-2026-78662 | HIGH | Patched | 7.5 | 2026-09-02 | Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking th… |
| CVE-2026-56855 | HIGH | Patched | 7.5 | 2026-09-02 | Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channe… |
| CVE-2023-20577 | HIGH | 7.4 | 2026-09-02 | A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution. | |
| CVE-2023-20576 | HIGH | 7.7 | 2026-09-02 | Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation. | |
| CVE-2026-84841 | HIGH | 7.3 | 2026-09-02 | A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enforcement of se… | |
| CVE-2026-84382 | HIGH | Patched | 7.5 | 2026-09-02 | HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or … |
| CVE-2026-84381 | HIGH | Patched | 8.1 | 2026-09-02 | HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore… |
| CVE-2026-49832 | HIGH | Patched | 8.0 | 2026-09-02 | DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before … |
| CVE-2026-82404 | HIGH | Patched | 8.3 | 2026-09-02 | TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype … |
| CVE-2026-79755 | HIGH | Patched | 8.0 | 2026-09-02 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, on the Nuclio local Docker platform, the function namespace is interpo… |
| CVE-2026-53635 | HIGH | 7.6 | 2026-09-02 | Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 59bb6d6, the view function set_course_mode_price() at lms/djangoapps/i… | |
| CVE-2026-52833 | HIGH | Patched | 8.0 | 2026-09-02 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function bu… |
| CVE-2026-52831 | HIGH | Patched | 8.0 | 2026-09-02 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron tr… |