Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 2,372 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85429 | HIGH | 7.5 | 2026-09-03 | MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_M… | |
| CVE-2026-85428 | CRITICAL | 9.8 | 2026-09-03 | MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Att… | |
| CVE-2026-85427 | HIGH | 8.1 | 2026-09-03 | MOOS essential-moos pAntler through 10.0.1 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary programs by publishing … | |
| CVE-2026-85426 | CRITICAL | 9.8 | 2026-09-03 | MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into clie… | |
| CVE-2026-85425 | CRITICAL | 9.8 | 2026-09-03 | MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsanitized text to a shell command. Attackers can … | |
| CVE-2026-85424 | CRITICAL | 9.8 | 2026-09-03 | MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privil… | |
| CVE-2026-85414 | MEDIUM | 6.4 | 2026-09-05 | The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute in all versions up to, and including, 3… | |
| CVE-2026-85409 | MEDIUM | 6.3 | 2026-09-04 | A vulnerability was identified in Eleveo Quality Management 9.7.0. The affected element is the function QuestionnaireService.runDataExportNow of the component Questionnaire… | |
| CVE-2026-85408 | MEDIUM | 4.3 | 2026-09-04 | A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the compone… | |
| CVE-2026-85407 | MEDIUM | 4.3 | 2026-09-04 | A vulnerability was found in Eleveo Quality Management 9.7.0. This issue affects some unknown processing of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the c… | |
| CVE-2026-85406 | LOW | 3.5 | 2026-09-04 | A vulnerability has been found in Eleveo Quality Management 9.7.0. This vulnerability affects unknown code of the component Conversation Review. The manipulation leads to c… | |
| CVE-2026-85405 | LOW | 3.5 | 2026-09-04 | A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/roleAddAction.do. Executing a manipulation of the argument … | |
| CVE-2026-85403 | HIGH | 7.3 | 2026-09-04 | A flaw has been found in code-projects Doctor Appointment System 1.0. This issue affects some unknown processing of the file /contactus.php. This manipulation of the argume… | |
| CVE-2026-85402 | HIGH | 7.3 | 2026-09-04 | A vulnerability was detected in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient/booking.php. The manipulation of t… | |
| CVE-2026-85401 | MEDIUM | 6.3 | 2026-09-04 | A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connector… | |
| CVE-2026-85400 | NONE | — | 2026-09-08 | Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This al… | |
| CVE-2026-85399 | HIGH | 7.3 | 2026-09-04 | A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the function getSinglePresp of the file includes/pre… | |
| CVE-2026-85398 | HIGH | 7.3 | 2026-09-04 | A vulnerability was identified in code-projects Hospital Information System 1.0. Affected is the function viewReq of the file viewReq.php. Such manipulation of the argument… | |
| CVE-2026-85397 | HIGH | 7.3 | 2026-09-04 | A vulnerability was determined in code-projects Hospital Information System 1.0. This impacts the function findBySearch of the file addReq.php. This manipulation of the arg… | |
| CVE-2026-85396 | HIGH | Patched | 7.5 | 2026-09-03 | rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without … |
| CVE-2026-85395 | HIGH | Patched | 7.1 | 2026-09-03 | UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers wit… |
| CVE-2026-85394 | CRITICAL | 9.1 | 2026-09-03 | python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attacker… | |
| CVE-2026-85393 | HIGH | 7.5 | 2026-09-03 | node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage byte… | |
| CVE-2026-85392 | MEDIUM | 4.3 | 2026-09-03 | Peppermint through 0.5.5 contains an authorization bypass vulnerability in the GET /api/v1/auth/user/:id/logout endpoint that allows authenticated attackers to delete sessi… | |
| CVE-2026-85391 | CRITICAL | 9.8 | 2026-09-03 | Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attack… |