Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 451–475 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-53635 HIGH 7.6 2026-09-02 Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 59bb6d6, the view function set_course_mode_price() at lms/djangoapps/i…
CVE-2026-53636 MEDIUM 4.7 2026-09-02 Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 3a5ac85, a security vulnerability has been identified in the Open edX …
CVE-2026-53649 CRITICAL Patched 9.6 2026-09-02 Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a …
CVE-2026-53670 NONE Patched — 2026-09-02 PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, in the Prevail eBPF verifier, EbpfTransformer::add() silently …
CVE-2026-53671 NONE Patched — 2026-09-02 PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the abstract transformer in prevail treats writes through a T_…
CVE-2026-53682 MEDIUM 5.3 2026-09-01 An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA …
CVE-2026-53683 MEDIUM 4.3 2026-09-02 reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by …
CVE-2026-53706 NONE Patched — 2026-09-02 PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the prevail eBPF verifier accepts ALU32 ADD and SUB instructio…
CVE-2026-53720 NONE Patched — 2026-09-03 pymonocypher uses cython to wrap the Monocypher C library. Prior to version 4.0.2.8, the argon2i_32 implementation does not check the nb_blocks size. If the caller does not…
CVE-2026-53728 HIGH Patched 7.1 2026-09-03 Medplum is a developer platform that enables development of healthcare apps. Prior to version 5.1.6, the external identity provider callback at GET /auth/external accepts a…
CVE-2026-53756 MEDIUM Patched 4.9 2026-09-04 Emlog is an open source website building system. Prior to version 2.6.16, Emlog CMS Pro contains a blind SQL injection in User_Model::getUserDataByLogin(). The $account par…
CVE-2026-53757 NONE — 2026-09-04 Emlog is an open source website building system. In versions 2.6.29 and prior, the emUnZip() function extracts all ZIP entries via ZipArchive::extractTo() without validatin…
CVE-2026-53758 NONE — 2026-09-04 Emlog is an open source website building system. In versions 2.6.29 and prior, article content is processed by Parsedown without enabling safe mode, which means raw HTML in…
CVE-2026-53760 MEDIUM 5.2 2026-09-04 Admidio is an open-source user management solution. In versions 5.0.11 and prior, the modules/plugins.php endpoint handles plugin installation, uninstallation, and update o…
CVE-2026-53761 NONE Patched — 2026-09-04 Frappe CRM is an open-source customer relationship management tool. Prior to version 1.73.0, there is an authentication bypass vulnerability via logged invitation keys in c…
CVE-2026-53769 MEDIUM Patched 6.5 2026-09-04 Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side up…
CVE-2026-53924 NONE Patched — 2026-09-03 Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. Pri…
CVE-2026-53932 HIGH Patched 8.0 2026-09-04 laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during d…
CVE-2026-5480 NONE — 2026-09-01 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have be…
CVE-2026-5522 MEDIUM 6.7 2026-09-04 IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authenticati…
CVE-2026-55221 MEDIUM Patched 6.5 2026-09-02 Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.10.0, Boruta…
CVE-2026-55421 MEDIUM 6.8 2026-09-02 Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 00b7c3c, the endpoint accepts user-supplied files[].url, performs a se…
CVE-2026-55512 MEDIUM Patched 5.3 2026-09-04 nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.2.0 to before version 0.5.0, when OIDC is enabled, GET /ui/oidc/login is reachable with…
CVE-2026-55513 MEDIUM Patched 5.4 2026-09-04 nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI host-creation path ignores both the…
CVE-2026-55658 HIGH 7.7 2026-09-03 Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In …