Search
78,575 CVEs
CVEs (78,575, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 78,575 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77104 | NONE | Patched | — | 2026-09-08 | CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe. |
| CVE-2026-77105 | NONE | Patched | — | 2026-09-08 | CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServ… |
| CVE-2026-77106 | NONE | Patched | — | 2026-09-08 | Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvaul… |
| CVE-2026-77089 | NONE | Patched | — | 2026-09-08 | Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center. |
| CVE-2026-77091 | NONE | Patched | — | 2026-09-08 | DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and I… |
| CVE-2026-77092 | NONE | Patched | — | 2026-09-08 | Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Con… |
| CVE-2026-77097 | NONE | Patched | — | 2026-09-08 | Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved … |
| CVE-2026-77098 | NONE | Patched | — | 2026-09-08 | Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metric… |
| CVE-2026-77101 | NONE | Patched | — | 2026-09-08 | CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe. |
| CVE-2026-77102 | NONE | Patched | — | 2026-09-08 | CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe. |
| CVE-2026-62437 | NONE | — | 2026-09-08 | When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and the associated removal of trackin… | |
| CVE-2026-19203 | NONE | — | 2026-09-08 | A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, poten… | |
| CVE-2026-11573 | NONE | — | 2026-09-08 | Uncontrolled recursion in Qt's QDomDocument serialization (QtXml) lets deeply nested untrusted XML crash the app via stack exhaustion (DoS only). | |
| CVE-2026-12611 | NONE | — | 2026-09-08 | A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole ser… | |
| CVE-2026-77654 | NONE | — | 2026-09-08 | Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Inj… | |
| CVE-2026-19614 | NONE | — | 2026-09-08 | The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3. | |
| CVE-2026-85400 | NONE | — | 2026-09-08 | Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This al… | |
| CVE-2026-86590 | NONE | Patched | — | 2026-09-08 | In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP… |
| CVE-2026-77132 | NONE | — | 2026-09-08 | It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged … | |
| CVE-2026-75811 | NONE | — | 2026-09-08 | Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause h… | |
| CVE-2026-18023 | NONE | — | 2026-09-08 | Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via … | |
| CVE-2026-19397 | NONE | — | 2026-09-08 | Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the… | |
| CVE-2026-75808 | NONE | — | 2026-09-08 | Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by by… | |
| CVE-2026-75809 | NONE | — | 2026-09-08 | Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver au… | |
| CVE-2026-75810 | NONE | — | 2026-09-08 | Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigg… |