Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 2,372 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19203 | NONE | — | 2026-09-08 | A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, poten… | |
| CVE-2026-86541 | HIGH | Patched | 8.3 | 2026-09-07 | knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the proj… |
| CVE-2026-86295 | HIGH | 8.3 | 2026-09-07 | A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of t… | |
| CVE-2026-84173 | NONE | — | 2026-09-07 | In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a… | |
| CVE-2026-82751 | NONE | Patched | — | 2026-09-06 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a lar… |
| CVE-2026-82750 | NONE | Patched | — | 2026-09-06 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a lar… |
| CVE-2026-52769 | HIGH | Patched | 8.3 | 2026-09-05 | YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route - exposed publicly with acl:"public" - a… |
| CVE-2026-52771 | HIGH | Patched | 8.3 | 2026-09-05 | YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a page tag retrieved from the database into a … |
| CVE-2026-57164 | NONE | — | 2026-09-04 | PJSIP is a free and open source multimedia communication library written in C. Prior to commit 8d5956a, a heap buffer overflow exists in the PJLIB-UTIL HTTP client (http_cl… | |
| CVE-2026-85538 | NONE | — | 2026-09-04 | An incorrect authorization vulnerability in MISP allowed authenticated users to delete attributes from events despite lacking the required perm_modify or perm_modify_org pe… | |
| CVE-2026-85048 | HIGH | 8.3 | 2026-09-03 | Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside t… | |
| CVE-2026-84736 | NONE | — | 2026-09-03 | In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for … | |
| CVE-2026-85212 | HIGH | 8.3 | 2026-09-03 | CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrat… | |
| CVE-2026-82404 | HIGH | Patched | 8.3 | 2026-09-02 | TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype … |
| CVE-2026-45730 | HIGH | Patched | 8.3 | 2026-09-02 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0, there is a vulnerability in Nuclio Dashboard's project management API,… |
| CVE-2026-77180 | HIGH | 8.3 | 2026-09-02 | When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple… | |
| CVE-2026-84335 | HIGH | Patched | 8.3 | 2026-09-02 | Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineer… |
| CVE-2026-84349 | HIGH | Patched | 8.3 | 2026-09-02 | Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the s… |
| CVE-2026-84351 | HIGH | Patched | 8.3 | 2026-09-02 | Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code ou… |
| CVE-2026-73780 | HIGH | Patched | 8.3 | 2026-09-01 | A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a… |
| CVE-2026-73708 | HIGH | Patched | 8.3 | 2026-09-01 | A business logic vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to obta… |
| CVE-2026-73709 | HIGH | Patched | 8.3 | 2026-09-01 | A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to run arbitrary commands on the under… |
| CVE-2026-63137 | HIGH | Patched | 8.3 | 2026-09-01 | Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holdin… |
| CVE-2026-8712 | HIGH | Patched | 8.3 | 2026-09-01 | Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitr… |
| CVE-2026-84115 | HIGH | 8.3 | 2026-09-01 | A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handle… |