Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

12,997 CVEs

CVEs (12,997, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 26–50 of 12,997 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9324 NONE — 2026-08-21 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-9321 NONE — 2026-08-21 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-9318 MEDIUM 5.4 2026-08-12 tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedd…
CVE-2026-9317 HIGH Patched 8.1 2026-09-04 Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by …
CVE-2026-9254 NONE — 2026-08-24 An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and …
CVE-2026-9244 NONE — 2026-08-21 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-9214 NONE — 2026-08-11 Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modificati…
CVE-2026-9186 MEDIUM 6.5 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 h…
CVE-2026-9138 MEDIUM 6.5 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFi…
CVE-2026-9055 CRITICAL 9.8 2026-09-02 The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insuf…
CVE-2026-9052 NONE — 2026-08-21 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-9036 MEDIUM 5.9 2026-09-03 IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitiv…
CVE-2026-9033 NONE — 2026-08-20 An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout o…
CVE-2026-9012 NONE — 2026-08-21 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-8917 NONE — 2026-08-11 Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an arbit…
CVE-2026-8862 HIGH 7.5 2026-09-03 IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container regis…
CVE-2026-8840 MEDIUM 5.3 2026-08-15 The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.36. This is due to the…
CVE-2026-8810 MEDIUM 6.9 2026-08-19 On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables.
CVE-2026-8718 HIGH 8.4 2026-08-10 tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied …
CVE-2026-8717 NONE — 2026-08-20 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-8715 CRITICAL Patched 9.6 2026-08-13 Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allo…
CVE-2026-8712 HIGH Patched 8.3 2026-09-01 Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitr…
CVE-2026-8667 MEDIUM Patched 4.3 2026-08-12 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions cou…
CVE-2026-86597 MEDIUM 6.5 2026-09-08 Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encrypti…
CVE-2026-86590 NONE Patched — 2026-09-08 In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP…