Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

163,528 CVEs · Medium severity

CVEs (163,528, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 476–500 of 163,528 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-71403 MEDIUM Patched 6.1 2026-09-03 A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and `principalIds` fields. A user holding the `u…
CVE-2026-63694 MEDIUM 5.0 2026-09-03 Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. …
CVE-2026-56126 MEDIUM Patched 5.4 2026-09-03 pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Status: Monitoring privilege to inject arbitrary JavaScript via graph configuration paramet…
CVE-2026-56127 MEDIUM Patched 5.4 2026-09-03 pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Rules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /…
CVE-2026-56128 MEDIUM Patched 5.4 2026-09-03 pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Schedules: Edit privilege to inject arbitrary JavaScript via the descr parameter …
CVE-2026-35160 MEDIUM 5.0 2026-09-03 Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerab…
CVE-2026-84815 MEDIUM 5.8 2026-09-03 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold allows Reflected XSS. This issue affects Enfold: from n…
CVE-2026-85161 MEDIUM 4.3 2026-09-03 AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster.php that lacks forbidIfNotPost or forbidIfInvalidToken checks. Attackers…
CVE-2026-85162 MEDIUM 6.5 2026-09-03 AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in plugin/Live/saveLive.php that lacks forbidIfNotPost and forbidIfInvalidToken protecti…
CVE-2026-85163 MEDIUM 6.5 2026-09-03 AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the EPG parser that allows authenticated uploaders to fetch arbitrary internal URLs.…
CVE-2026-85156 MEDIUM 5.3 2026-09-03 WWBN AVideo fails to properly validate access controls on the public channel page, allowing unauthenticated visitors to view unlisted and group-restricted videos through ha…
CVE-2026-85157 MEDIUM 5.3 2026-09-03 WWBN AVideo contains a broken access control vulnerability in the unauthenticated feed/index.php endpoint that disables per-video visibility checks when a program_id parame…
CVE-2026-85158 MEDIUM 5.4 2026-09-03 AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in videoEmbeded.php that echoes the link parameter inside an HTML comment with zero …
CVE-2026-85159 MEDIUM 5.4 2026-09-03 AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php where the cancelUri parameter is echoed in an href attribute after …
CVE-2026-85100 MEDIUM 4.3 2026-09-03 A vulnerability was detected in 2FastLabs agent-squad up to 1.1.4. Affected by this vulnerability is the function AgentSquad.routeRequest of the file agent-squad/typescript…
CVE-2026-85106 MEDIUM 6.3 2026-09-03 A vulnerability has been found in NousResearch hermes-agent 0.18.0. This affects the function fetchLinkTitle of the file apps/desktop/src/app/artifacts/index.tsx of the com…
CVE-2026-85107 MEDIUM 4.3 2026-09-03 A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability affects the function resourceBufferFromUrl of the file apps/desktop/electron/main.ts of th…
CVE-2026-85084 MEDIUM 6.3 2026-09-03 Out-of-bounds Write and Improper Validation of Array Index vulnerability in Samsung Open Source TizenFX Samsung/TizenFX allows Overflow Buffers.
CVE-2026-85089 MEDIUM Patched 6.5 2026-09-03 FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/c…
CVE-2026-85090 MEDIUM Patched 5.4 2026-09-03 FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP s…
CVE-2026-85092 MEDIUM 6.6 2026-09-03 LiME through 1.12.0 fails to validate the disk acquisition output path and does not use O_NOFOLLOW when opening the operator-supplied path parameter, allowing unprivileged …
CVE-2026-85093 MEDIUM 6.5 2026-09-03 Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points. Authenticated attackers …
CVE-2026-85021 MEDIUM 4.3 2026-09-03 A vulnerability was determined in langgenius dify 1.13.0. Affected is the function router.replace of the file web/app/(shareLayout)/components/splash.tsx of the component S…
CVE-2026-85040 MEDIUM 4.7 2026-09-03 A weakness has been identified in ZhongBangKeJi CRMEB up to 6.0.0. Affected by this vulnerability is the function eval of the file /adminapi/system/crontab/save of the comp…
CVE-2026-82918 MEDIUM 5.5 2026-09-03 XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity references. If a user opens a specially crafted setting fi…