Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 2,372 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84226 | NONE | — | 2026-09-07 | OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps | |
| CVE-2026-85651 | HIGH | Patched | 8.5 | 2026-09-04 | Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary … |
| CVE-2026-85616 | HIGH | Patched | 8.5 | 2026-09-04 | Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authentica… |
| CVE-2026-4644 | NONE | — | 2026-09-04 | A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated… | |
| CVE-2026-67397 | NONE | — | 2026-09-04 | Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root. | |
| CVE-2026-70178 | HIGH | 8.5 | 2026-09-03 | Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-65818 | HIGH | 8.5 | 2026-09-03 | Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-69857 | HIGH | 8.5 | 2026-09-03 | Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network. | |
| CVE-2026-85179 | HIGH | 8.5 | 2026-09-03 | Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud me… | |
| CVE-2026-9854 | NONE | — | 2026-09-03 | A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying W… | |
| CVE-2026-9853 | NONE | — | 2026-09-03 | A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects wi… | |
| CVE-2026-73707 | HIGH | Patched | 8.5 | 2026-09-01 | Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to… |
| CVE-2026-16675 | NONE | — | 2026-09-01 | A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible consol… | |
| CVE-2026-86502 | HIGH | Patched | 8.4 | 2026-09-07 | In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts |
| CVE-2026-19843 | HIGH | 8.4 | 2026-09-07 | A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell co… | |
| CVE-2026-20501 | HIGH | 8.4 | 2026-09-07 | In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges nee… | |
| CVE-2026-20502 | HIGH | 8.4 | 2026-09-07 | In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges nee… | |
| CVE-2026-57159 | NONE | — | 2026-09-04 | PJSIP is a free and open source multimedia communication library written in C. Prior to commit 673b978, a remote out-of-bounds read and write can occur in the SDP negotiato… | |
| CVE-2025-12737 | HIGH | 8.4 | 2026-09-03 | The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative… | |
| CVE-2026-80753 | HIGH | 8.4 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: ovpn: run deferred work on a module-owned workqueue ovpn queues several work items whose callbacks exe… | |
| CVE-2026-80745 | HIGH | 8.4 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: regulator: fp9931: Fix VPOS/VNEG voltage selector table The VPOSNEG_table[] mapping does not match the… | |
| CVE-2026-80750 | HIGH | 8.4 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix remaining %pOF after of_node_put() scpsys_get_bus_protection_legacy() looks up… | |
| CVE-2026-80752 | HIGH | 8.4 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: Input: psxpad-spi - set driver data before use psxpad_spi_suspend() retrieves the controller state wit… | |
| CVE-2026-73781 | HIGH | Patched | 8.4 | 2026-09-01 | A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a… |
| CVE-2026-77104 | NONE | Patched | — | 2026-09-08 | CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe. |