Search
163,207 CVEs · Medium severity
EOL hidden · Show all products
CVEs (163,207, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 163,207 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-82525 | MEDIUM | Patched | 5.5 | 2026-09-03 | Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by embedd… |
| CVE-2026-50554 | MEDIUM | Patched | 5.3 | 2026-09-03 | Note Mark is an open-source note-taking application. Prior to version 0.19.5, GET /api/books/{bookID}/notes is an unauthenticated endpoint that accepts a "deleted" query pa… |
| CVE-2026-85210 | MEDIUM | 4.3 | 2026-09-03 | Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. A… | |
| CVE-2026-85177 | MEDIUM | 5.4 | 2026-09-03 | CRMEB through 6.0.0 fails to validate message ownership in the edit_message handler of MessageSystemController.php, allowing authenticated users to modify arbitrary system … | |
| CVE-2026-85135 | MEDIUM | 6.3 | 2026-09-03 | A security flaw has been discovered in ILIAS up to 9.21/10.9/11.2. This affects the function ilObjMediaObjectGUI::uploadMultipleSubtitleFileObject of the file Services/Repo… | |
| CVE-2026-84971 | MEDIUM | 6.5 | 2026-09-03 | Improper handling of an unexpected value size in the decryption path of a client-side encryption library can cause a failed internal check that terminates the process using… | |
| CVE-2026-84970 | MEDIUM | 6.2 | 2026-09-03 | A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who controls the text that an embedding application ha… | |
| CVE-2026-71403 | MEDIUM | Patched | 6.1 | 2026-09-03 | A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and `principalIds` fields. A user holding the `u… |
| CVE-2026-63694 | MEDIUM | 5.0 | 2026-09-03 | Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. … | |
| CVE-2026-56128 | MEDIUM | Patched | 5.4 | 2026-09-03 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Schedules: Edit privilege to inject arbitrary JavaScript via the descr parameter … |
| CVE-2026-56127 | MEDIUM | Patched | 5.4 | 2026-09-03 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Rules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /… |
| CVE-2026-56126 | MEDIUM | Patched | 5.4 | 2026-09-03 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Status: Monitoring privilege to inject arbitrary JavaScript via graph configuration paramet… |
| CVE-2026-35160 | MEDIUM | 5.0 | 2026-09-03 | Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerab… | |
| CVE-2026-84815 | MEDIUM | 5.8 | 2026-09-03 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold allows Reflected XSS. This issue affects Enfold: from n… | |
| CVE-2026-85163 | MEDIUM | 6.5 | 2026-09-03 | AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the EPG parser that allows authenticated uploaders to fetch arbitrary internal URLs.… | |
| CVE-2026-85162 | MEDIUM | 6.5 | 2026-09-03 | AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in plugin/Live/saveLive.php that lacks forbidIfNotPost and forbidIfInvalidToken protecti… | |
| CVE-2026-85161 | MEDIUM | 4.3 | 2026-09-03 | AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster.php that lacks forbidIfNotPost or forbidIfInvalidToken checks. Attackers… | |
| CVE-2026-85159 | MEDIUM | 5.4 | 2026-09-03 | AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php where the cancelUri parameter is echoed in an href attribute after … | |
| CVE-2026-85158 | MEDIUM | 5.4 | 2026-09-03 | AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in videoEmbeded.php that echoes the link parameter inside an HTML comment with zero … | |
| CVE-2026-85157 | MEDIUM | 5.3 | 2026-09-03 | WWBN AVideo contains a broken access control vulnerability in the unauthenticated feed/index.php endpoint that disables per-video visibility checks when a program_id parame… | |
| CVE-2026-85156 | MEDIUM | 5.3 | 2026-09-03 | WWBN AVideo fails to properly validate access controls on the public channel page, allowing unauthenticated visitors to view unlisted and group-restricted videos through ha… | |
| CVE-2026-85107 | MEDIUM | 4.3 | 2026-09-03 | A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability affects the function resourceBufferFromUrl of the file apps/desktop/electron/main.ts of th… | |
| CVE-2026-85106 | MEDIUM | 6.3 | 2026-09-03 | A vulnerability has been found in NousResearch hermes-agent 0.18.0. This affects the function fetchLinkTitle of the file apps/desktop/src/app/artifacts/index.tsx of the com… | |
| CVE-2026-85100 | MEDIUM | 4.3 | 2026-09-03 | A vulnerability was detected in 2FastLabs agent-squad up to 1.1.4. Affected by this vulnerability is the function AgentSquad.routeRequest of the file agent-squad/typescript… | |
| CVE-2026-85093 | MEDIUM | 6.5 | 2026-09-03 | Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points. Authenticated attackers … |