Search
12,997 CVEs
CVEs (12,997, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 12,997 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-82584 | NONE | Patched | — | 2026-09-07 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project igniter allows a malicious package publisher to forge the mix igniter.install con… |
| CVE-2026-86287 | NONE | Patched | — | 2026-09-07 | Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths. Non-numeric and non-ASCII prefix lengths are accepted and treated as 0. Integers over 31 bits a… |
| CVE-2026-16028 | NONE | Patched | — | 2026-09-07 | Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table. When a stream re… |
| CVE-2026-86452 | NONE | — | 2026-09-07 | Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/… | |
| CVE-2026-86440 | NONE | — | 2026-09-07 | Affected versions of MISP insufficiently validate URLs used by dashboard widgets, particularly the Button widget. The widget's URL is stored configuration controlled by a… | |
| CVE-2026-86441 | NONE | — | 2026-09-07 | Affected versions of MISP contain inconsistent authorization checks across dashboard widgets that display organisation information. Several organisation-related widgets d… | |
| CVE-2026-86451 | NONE | — | 2026-09-07 | Affected versions of MISP allow authenticated users to retrieve object-reference records by UUID through EventGraphTool::get_reference_data() without first checking whether… | |
| CVE-2026-86426 | NONE | Patched | — | 2026-09-07 | LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeri… |
| CVE-2026-86408 | NONE | — | 2026-09-07 | Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queri… | |
| CVE-2026-86417 | NONE | — | 2026-09-07 | Affected versions of MISP inconsistently enforced email-address visibility in DashboardsController::listTemplates(). The query always fetched User.email, while redaction … | |
| CVE-2026-86418 | NONE | — | 2026-09-07 | Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal or… | |
| CVE-2026-86419 | NONE | — | 2026-09-07 | Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processin… | |
| CVE-2026-78325 | NONE | — | 2026-09-07 | Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the… | |
| CVE-2026-86351 | NONE | — | 2026-09-07 | Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /. That check is insufficient because protocol-rela… | |
| CVE-2026-82325 | NONE | — | 2026-09-07 | A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages | |
| CVE-2026-85201 | NONE | — | 2026-09-07 | In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Cont… | |
| CVE-2026-19204 | NONE | — | 2026-09-07 | A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exha… | |
| CVE-2026-86347 | NONE | — | 2026-09-07 | Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This … | |
| CVE-2026-84173 | NONE | — | 2026-09-07 | In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a… | |
| CVE-2026-86342 | NONE | — | 2026-09-07 | Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes fro… | |
| CVE-2026-84186 | NONE | — | 2026-09-07 | Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarde… | |
| CVE-2026-84732 | NONE | — | 2026-09-07 | Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a t… | |
| CVE-2026-14297 | NONE | — | 2026-09-07 | A buffer overflow in the Bluetooth Continuous Glucose Monitoring Service (CGMS) Record Access Control Point (RACP) write handler allows an authenticated BLE peer … | |
| CVE-2026-18796 | NONE | — | 2026-09-07 | Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally st… | |
| CVE-2026-81738 | NONE | — | 2026-09-07 | OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries |