Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 30,217 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23586 | NONE | — | 2026-09-02 | Rejected reason: Withdrawn by requester. | |
| CVE-2026-23587 | NONE | — | 2026-09-02 | Rejected reason: Withdrawn by requester. | |
| CVE-2026-23588 | NONE | — | 2026-09-02 | Rejected reason: Withdrawn by requester. | |
| CVE-2026-23589 | NONE | — | 2026-09-02 | Rejected reason: Withdrawn by requester. | |
| CVE-2026-23590 | NONE | — | 2026-09-02 | Rejected reason: Withdrawn by requester. | |
| CVE-2026-23591 | NONE | — | 2026-09-02 | Rejected reason: Withdrawn by requester. | |
| CVE-2026-23583 | NONE | — | 2026-09-02 | Rejected reason: Withdrawn by requester. | |
| CVE-2026-19754 | NONE | — | 2026-09-02 | Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify formula fields can provid… | |
| CVE-2026-84481 | NONE | — | 2026-09-01 | WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to… | |
| CVE-2026-18730 | NONE | Patched | — | 2026-09-01 | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send craft… |
| CVE-2026-84361 | NONE | Patched | — | 2026-09-01 | Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted co… |
| CVE-2026-84310 | NONE | Patched | — | 2026-09-01 | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes… |
| CVE-2026-84311 | NONE | Patched | — | 2026-09-01 | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.ext… |
| CVE-2026-84309 | NONE | Patched | — | 2026-09-01 | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py T… |
| CVE-2026-77221 | NONE | — | 2026-09-01 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-77222 | NONE | — | 2026-09-01 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-77223 | NONE | — | 2026-09-01 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-84303 | NONE | Patched | — | 2026-09-01 | gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names… |
| CVE-2026-84304 | NONE | Patched | — | 2026-09-01 | gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBu… |
| CVE-2026-84305 | NONE | Patched | — | 2026-09-01 | sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse.format(sql, reindent=True) and sqlformat --reindent route attacker-controlled parenthesi… |
| CVE-2026-52023 | NONE | — | 2026-09-01 | An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_p… | |
| CVE-2024-7952 | NONE | — | 2026-09-01 | A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be reached without authenticatio… | |
| CVE-2024-7953 | NONE | — | 2026-09-01 | A vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a threat actor could creat… | |
| CVE-2026-83616 | NONE | Patched | — | 2026-09-01 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom … |
| CVE-2026-83617 | NONE | Patched | — | 2026-09-01 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.11 until 0.9.12, the requireWellFormed: true element and … |