Search
2,281 CVEs
CVEs (2,281, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 2,281 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84852 | MEDIUM | 4.4 | 2026-09-02 | A security vulnerability has been detected in Reader Tools PDF Reader App 98.8 on Android. The affected element is the function ActSplashNew.handleDeeplink of the component… | |
| CVE-2026-49830 | MEDIUM | Patched | 4.4 | 2026-09-02 | DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, when ingesting an a… |
| CVE-2026-84442 | MEDIUM | 4.4 | 2026-09-02 | A vulnerability was identified in MapQuest Get Directions App 10.16.1 on Android. This vulnerability affects the function getDataColumn of the file ExpoShareIntentModule.kt… | |
| CVE-2026-84431 | MEDIUM | 4.4 | 2026-09-02 | A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component … | |
| CVE-2026-73739 | MEDIUM | Patched | 4.4 | 2026-09-01 | A vulnerability exists in the API of HPE Networking Fabric Composer that allows for an attacker with administrative privileges to access sensitive information in a cleartex… |
| CVE-2026-73740 | MEDIUM | Patched | 4.4 | 2026-09-01 | A local privilege escalation vulnerability in HPE Networking Fabric Composer could allow an authenticated privileged user on the underlying host to elevate their user privi… |
| CVE-2026-76959 | MEDIUM | 4.6 | 2026-09-08 | SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low pri… | |
| CVE-2026-86484 | MEDIUM | Patched | 4.6 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS |
| CVE-2026-9852 | NONE | — | 2026-09-03 | A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, dep… | |
| CVE-2026-86516 | MEDIUM | 4.7 | 2026-09-08 | A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-… | |
| CVE-2026-80176 | MEDIUM | 4.7 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Plaintext Storage of a Password vulnerability. A l… | |
| CVE-2026-86271 | MEDIUM | 4.7 | 2026-09-07 | A vulnerability was found in FluentCMS up to 0.0.5. This affects the function GetAccessible of the file src/Backend/FluentCMS.Services/Permissions/PermissionManager.cs. Per… | |
| CVE-2026-86240 | MEDIUM | 4.7 | 2026-09-07 | A security flaw has been discovered in liufee FeehiCMS up to 2.1.1. This affects the function catchImage of the file backend/widgets/ueditor/Uploader.php of the component U… | |
| CVE-2026-19861 | MEDIUM | Patched | 4.7 | 2026-09-05 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML … |
| CVE-2026-85643 | MEDIUM | 4.7 | 2026-09-04 | A flaw has been found in code-projects Online Shopping System 1.0. Impacted is the function mysqli_query of the file admin/adduser.php. Executing a manipulation of the argu… | |
| CVE-2026-85040 | MEDIUM | 4.7 | 2026-09-03 | A weakness has been identified in ZhongBangKeJi CRMEB up to 6.0.0. Affected by this vulnerability is the function eval of the file /adminapi/system/crontab/save of the comp… | |
| CVE-2026-71224 | MEDIUM | 4.7 | 2026-09-03 | A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata withou… | |
| CVE-2026-71219 | MEDIUM | 4.7 | 2026-09-03 | A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-d… | |
| CVE-2026-53636 | MEDIUM | 4.7 | 2026-09-02 | Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 3a5ac85, a security vulnerability has been identified in the Open edX … | |
| CVE-2026-73738 | MEDIUM | Patched | 4.7 | 2026-09-01 | A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to view sens… |
| CVE-2026-79943 | MEDIUM | 4.8 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Validation of Certificate with Host Mism… | |
| CVE-2026-19862 | MEDIUM | Patched | 4.8 | 2026-09-06 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to th… |
| CVE-2026-80437 | MEDIUM | Patched | 4.8 | 2026-09-06 | The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content … |
| CVE-2026-80439 | MEDIUM | Patched | 4.8 | 2026-09-06 | The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes th… |
| CVE-2026-81571 | MEDIUM | Patched | 4.8 | 2026-09-02 | The Brave WordPress plugin before 0.8.8 does not prevent a URL parameter used to pre-fill a form field from being passed to WordPress's shortcode engine, allowing unauthent… |