Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 2,372 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53635 | HIGH | 7.6 | 2026-09-02 | Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 59bb6d6, the view function set_course_mode_price() at lms/djangoapps/i… | |
| CVE-2026-53636 | MEDIUM | 4.7 | 2026-09-02 | Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 3a5ac85, a security vulnerability has been identified in the Open edX … | |
| CVE-2026-53649 | CRITICAL | Patched | 9.6 | 2026-09-02 | Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a … |
| CVE-2026-53670 | NONE | Patched | — | 2026-09-02 | PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, in the Prevail eBPF verifier, EbpfTransformer::add() silently … |
| CVE-2026-53671 | NONE | Patched | — | 2026-09-02 | PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the abstract transformer in prevail treats writes through a T_… |
| CVE-2026-53682 | MEDIUM | 5.3 | 2026-09-01 | An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA … | |
| CVE-2026-53683 | MEDIUM | 4.3 | 2026-09-02 | reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by … | |
| CVE-2026-53706 | NONE | Patched | — | 2026-09-02 | PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the prevail eBPF verifier accepts ALU32 ADD and SUB instructio… |
| CVE-2026-53720 | NONE | Patched | — | 2026-09-03 | pymonocypher uses cython to wrap the Monocypher C library. Prior to version 4.0.2.8, the argon2i_32 implementation does not check the nb_blocks size. If the caller does not… |
| CVE-2026-53728 | HIGH | Patched | 7.1 | 2026-09-03 | Medplum is a developer platform that enables development of healthcare apps. Prior to version 5.1.6, the external identity provider callback at GET /auth/external accepts a… |
| CVE-2026-53756 | MEDIUM | Patched | 4.9 | 2026-09-04 | Emlog is an open source website building system. Prior to version 2.6.16, Emlog CMS Pro contains a blind SQL injection in User_Model::getUserDataByLogin(). The $account par… |
| CVE-2026-53757 | NONE | — | 2026-09-04 | Emlog is an open source website building system. In versions 2.6.29 and prior, the emUnZip() function extracts all ZIP entries via ZipArchive::extractTo() without validatin… | |
| CVE-2026-53758 | NONE | — | 2026-09-04 | Emlog is an open source website building system. In versions 2.6.29 and prior, article content is processed by Parsedown without enabling safe mode, which means raw HTML in… | |
| CVE-2026-53760 | MEDIUM | 5.2 | 2026-09-04 | Admidio is an open-source user management solution. In versions 5.0.11 and prior, the modules/plugins.php endpoint handles plugin installation, uninstallation, and update o… | |
| CVE-2026-53761 | NONE | Patched | — | 2026-09-04 | Frappe CRM is an open-source customer relationship management tool. Prior to version 1.73.0, there is an authentication bypass vulnerability via logged invitation keys in c… |
| CVE-2026-53769 | MEDIUM | Patched | 6.5 | 2026-09-04 | Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side up… |
| CVE-2026-53924 | NONE | Patched | — | 2026-09-03 | Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. Pri… |
| CVE-2026-53932 | HIGH | Patched | 8.0 | 2026-09-04 | laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during d… |
| CVE-2026-5480 | NONE | — | 2026-09-01 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have be… | |
| CVE-2026-5522 | MEDIUM | 6.7 | 2026-09-04 | IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authenticati… | |
| CVE-2026-55221 | MEDIUM | Patched | 6.5 | 2026-09-02 | Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.10.0, Boruta… |
| CVE-2026-55421 | MEDIUM | 6.8 | 2026-09-02 | Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 00b7c3c, the endpoint accepts user-supplied files[].url, performs a se… | |
| CVE-2026-55512 | MEDIUM | Patched | 5.3 | 2026-09-04 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.2.0 to before version 0.5.0, when OIDC is enabled, GET /ui/oidc/login is reachable with… |
| CVE-2026-55513 | MEDIUM | Patched | 5.4 | 2026-09-04 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI host-creation path ignores both the… |
| CVE-2026-55658 | HIGH | 7.7 | 2026-09-03 | Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In … |