Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

565 CVEs · published 2026-09-24 to 2026-09-24

CVEs (565, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 451–475 of 565 (capped at 500)

CVE ID Severity Patch CVSS Published ↓ Description
CVE-2026-51994 NONE — 2026-09-24 mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authen…
CVE-2026-19492 LOW 3.2 2026-09-24 IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interfa…
CVE-2026-18870 MEDIUM 4.3 2026-09-24 IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 could allow a remote attacker to…
CVE-2026-13467 HIGH 8.1 2026-09-24 Out-of-bounds write vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trus…
CVE-2026-13466 HIGH 8.1 2026-09-24 Incorrect calculation of buffer size vulnerability in Altera Trusted Firmware on HPS allows Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0.
CVE-2026-13465 HIGH 8.1 2026-09-24 Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affe…
CVE-2026-12559 NONE — 2026-09-24 A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain …
CVE-2026-97360 CRITICAL 10.0 2026-09-24 HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete file…
CVE-2026-97359 CRITICAL 10.0 2026-09-24 HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code exec…
CVE-2026-97062 MEDIUM 5.4 2026-09-24 Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG file…
CVE-2026-97061 MEDIUM 4.3 2026-09-24 Black Candy through 3.2.1 fails to scope playlist search queries to the authenticated session user, allowing any authenticated user to enumerate all playlists on the instan…
CVE-2026-97059 HIGH 8.2 2026-09-24 DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the …
CVE-2026-97058 MEDIUM 5.3 2026-09-24 sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions…
CVE-2026-97057 HIGH 7.5 2026-09-24 redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an exce…
CVE-2026-95521 HIGH 7.8 2026-09-24 A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an …
CVE-2026-95519 HIGH 7.8 2026-09-24 A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows,…
CVE-2026-91187 NONE Patched — 2026-09-24 Improper Verification of Cryptographic Signature vulnerability in dashbit nimble_zta allows an unauthenticated remote attacker to authenticate as an arbitrary Cloudflare se…
CVE-2026-88360 NONE — 2026-09-24 libvips 8.19.0 contains a memory access vulnerability when processing little-endian PFM images. If the PFM text header length is not a multiple of four bytes, the mmap-base…
CVE-2026-88359 NONE — 2026-09-24 libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted YAML document containing a very large literal or fold…
CVE-2026-77798 MEDIUM 6.5 2026-09-24 Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock management bug in the user management module.
CVE-2026-77797 LOW 3.6 2026-09-24 Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files.
CVE-2026-18857 LOW 3.4 2026-09-24 IBM OPENBMC FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in the BMC firmware management interfac…
CVE-2026-18104 LOW 3.3 2026-09-24 IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption.
CVE-2026-17511 LOW 3.4 2026-09-24 IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability i…
CVE-2026-17504 MEDIUM 5.1 2026-09-24 IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability i…