Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 451–475 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-84226 NONE — 2026-09-07 OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps
CVE-2026-85651 HIGH Patched 8.5 2026-09-04 Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary …
CVE-2026-85616 HIGH Patched 8.5 2026-09-04 Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authentica…
CVE-2026-4644 NONE — 2026-09-04 A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated…
CVE-2026-67397 NONE — 2026-09-04 Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.
CVE-2026-70178 HIGH 8.5 2026-09-03 Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
CVE-2026-65818 HIGH 8.5 2026-09-03 Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
CVE-2026-69857 HIGH 8.5 2026-09-03 Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
CVE-2026-85179 HIGH 8.5 2026-09-03 Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud me…
CVE-2026-9854 NONE — 2026-09-03 A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying W…
CVE-2026-9853 NONE — 2026-09-03 A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects wi…
CVE-2026-73707 HIGH Patched 8.5 2026-09-01 Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to…
CVE-2026-16675 NONE — 2026-09-01 A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible consol…
CVE-2026-86502 HIGH Patched 8.4 2026-09-07 In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts
CVE-2026-19843 HIGH 8.4 2026-09-07 A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell co…
CVE-2026-20501 HIGH 8.4 2026-09-07 In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges nee…
CVE-2026-20502 HIGH 8.4 2026-09-07 In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges nee…
CVE-2026-57159 NONE — 2026-09-04 PJSIP is a free and open source multimedia communication library written in C. Prior to commit 673b978, a remote out-of-bounds read and write can occur in the SDP negotiato…
CVE-2025-12737 HIGH 8.4 2026-09-03 The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative…
CVE-2026-80753 HIGH 8.4 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: ovpn: run deferred work on a module-owned workqueue ovpn queues several work items whose callbacks exe…
CVE-2026-80745 HIGH 8.4 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: regulator: fp9931: Fix VPOS/VNEG voltage selector table The VPOSNEG_table[] mapping does not match the…
CVE-2026-80750 HIGH 8.4 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix remaining %pOF after of_node_put() scpsys_get_bus_protection_legacy() looks up…
CVE-2026-80752 HIGH 8.4 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: Input: psxpad-spi - set driver data before use psxpad_spi_suspend() retrieves the controller state wit…
CVE-2026-73781 HIGH Patched 8.4 2026-09-01 A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a…
CVE-2026-77104 NONE Patched — 2026-09-08 CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.