Search
13,075 CVEs
EOL hidden · Show all products
CVEs (13,075, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 13,075 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-86283 | NONE | — | 2026-09-06 | MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access … | |
| CVE-2026-86217 | MEDIUM | 5.3 | 2026-09-06 | A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component … | |
| CVE-2026-86216 | MEDIUM | 4.3 | 2026-09-06 | A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The mani… | |
| CVE-2026-86215 | MEDIUM | 4.3 | 2026-09-06 | A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the file Front-end/server.php of the component Logout H… | |
| CVE-2026-86259 | HIGH | Patched | 7.5 | 2026-09-06 | OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. A… |
| CVE-2026-86258 | MEDIUM | 5.9 | 2026-09-06 | nbviewer through 1.0.1 contains a path traversal vulnerability in LocalFileHandler.can_show() that uses string-prefix comparison instead of proper path validation. Attacker… | |
| CVE-2026-86214 | HIGH | 7.3 | 2026-09-06 | A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument ema… | |
| CVE-2026-86213 | HIGH | 7.3 | 2026-09-06 | A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search H… | |
| CVE-2026-86257 | MEDIUM | Patched | 5.4 | 2026-09-06 | wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers c… |
| CVE-2026-86256 | MEDIUM | Patched | 5.4 | 2026-09-06 | wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). After a trainer enters impersonati… |
| CVE-2026-86255 | MEDIUM | Patched | 6.5 | 2026-09-06 | wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers … |
| CVE-2026-86254 | MEDIUM | 6.8 | 2026-09-06 | wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym-scope check using raw integer c… | |
| CVE-2026-86253 | MEDIUM | Patched | 5.9 | 2026-09-06 | h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments, event.url.pathname is not normalized, so percent-e… |
| CVE-2026-86252 | MEDIUM | Patched | 5.3 | 2026-09-06 | h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including… |
| CVE-2026-86251 | MEDIUM | Patched | 5.9 | 2026-09-06 | h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A double-decoding flaw allows a request path containing double-encoded dot sequ… |
| CVE-2026-86250 | HIGH | Patched | 7.5 | 2026-09-06 | h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attacke… |
| CVE-2026-86242 | HIGH | Patched | 8.1 | 2026-09-06 | Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is d… |
| CVE-2026-86212 | MEDIUM | 4.3 | 2026-09-06 | A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. T… | |
| CVE-2026-86205 | MEDIUM | Patched | 5.4 | 2026-09-06 | h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pat… |
| CVE-2022-51009 | HIGH | Patched | 7.5 | 2026-09-06 | PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin pack… |
| CVE-2022-51008 | MEDIUM | Patched | 5.3 | 2026-09-06 | PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without sending LoginPacket. Attackers … |
| CVE-2021-48007 | MEDIUM | Patched | 6.5 | 2026-09-06 | PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packet… |
| CVE-2021-48006 | LOW | Patched | 3.3 | 2026-09-06 | PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but on… |
| CVE-2020-37277 | MEDIUM | Patched | 6.5 | 2026-09-06 | PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send s… |
| CVE-2026-86211 | HIGH | 7.3 | 2026-09-06 | A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulati… |