Search
163,528 CVEs · Medium severity
CVEs (163,528, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 163,528 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71403 | MEDIUM | Patched | 6.1 | 2026-09-03 | A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and `principalIds` fields. A user holding the `u… |
| CVE-2026-63694 | MEDIUM | 5.0 | 2026-09-03 | Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. … | |
| CVE-2026-56126 | MEDIUM | Patched | 5.4 | 2026-09-03 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Status: Monitoring privilege to inject arbitrary JavaScript via graph configuration paramet… |
| CVE-2026-56127 | MEDIUM | Patched | 5.4 | 2026-09-03 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Rules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /… |
| CVE-2026-56128 | MEDIUM | Patched | 5.4 | 2026-09-03 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Schedules: Edit privilege to inject arbitrary JavaScript via the descr parameter … |
| CVE-2026-35160 | MEDIUM | 5.0 | 2026-09-03 | Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerab… | |
| CVE-2026-84815 | MEDIUM | 5.8 | 2026-09-03 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold allows Reflected XSS. This issue affects Enfold: from n… | |
| CVE-2026-85161 | MEDIUM | 4.3 | 2026-09-03 | AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster.php that lacks forbidIfNotPost or forbidIfInvalidToken checks. Attackers… | |
| CVE-2026-85162 | MEDIUM | 6.5 | 2026-09-03 | AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in plugin/Live/saveLive.php that lacks forbidIfNotPost and forbidIfInvalidToken protecti… | |
| CVE-2026-85163 | MEDIUM | 6.5 | 2026-09-03 | AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the EPG parser that allows authenticated uploaders to fetch arbitrary internal URLs.… | |
| CVE-2026-85156 | MEDIUM | 5.3 | 2026-09-03 | WWBN AVideo fails to properly validate access controls on the public channel page, allowing unauthenticated visitors to view unlisted and group-restricted videos through ha… | |
| CVE-2026-85157 | MEDIUM | 5.3 | 2026-09-03 | WWBN AVideo contains a broken access control vulnerability in the unauthenticated feed/index.php endpoint that disables per-video visibility checks when a program_id parame… | |
| CVE-2026-85158 | MEDIUM | 5.4 | 2026-09-03 | AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in videoEmbeded.php that echoes the link parameter inside an HTML comment with zero … | |
| CVE-2026-85159 | MEDIUM | 5.4 | 2026-09-03 | AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php where the cancelUri parameter is echoed in an href attribute after … | |
| CVE-2026-85100 | MEDIUM | 4.3 | 2026-09-03 | A vulnerability was detected in 2FastLabs agent-squad up to 1.1.4. Affected by this vulnerability is the function AgentSquad.routeRequest of the file agent-squad/typescript… | |
| CVE-2026-85106 | MEDIUM | 6.3 | 2026-09-03 | A vulnerability has been found in NousResearch hermes-agent 0.18.0. This affects the function fetchLinkTitle of the file apps/desktop/src/app/artifacts/index.tsx of the com… | |
| CVE-2026-85107 | MEDIUM | 4.3 | 2026-09-03 | A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability affects the function resourceBufferFromUrl of the file apps/desktop/electron/main.ts of th… | |
| CVE-2026-85084 | MEDIUM | 6.3 | 2026-09-03 | Out-of-bounds Write and Improper Validation of Array Index vulnerability in Samsung Open Source TizenFX Samsung/TizenFX allows Overflow Buffers. | |
| CVE-2026-85089 | MEDIUM | Patched | 6.5 | 2026-09-03 | FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/c… |
| CVE-2026-85090 | MEDIUM | Patched | 5.4 | 2026-09-03 | FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP s… |
| CVE-2026-85092 | MEDIUM | 6.6 | 2026-09-03 | LiME through 1.12.0 fails to validate the disk acquisition output path and does not use O_NOFOLLOW when opening the operator-supplied path parameter, allowing unprivileged … | |
| CVE-2026-85093 | MEDIUM | 6.5 | 2026-09-03 | Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points. Authenticated attackers … | |
| CVE-2026-85021 | MEDIUM | 4.3 | 2026-09-03 | A vulnerability was determined in langgenius dify 1.13.0. Affected is the function router.replace of the file web/app/(shareLayout)/components/splash.tsx of the component S… | |
| CVE-2026-85040 | MEDIUM | 4.7 | 2026-09-03 | A weakness has been identified in ZhongBangKeJi CRMEB up to 6.0.0. Affected by this vulnerability is the function eval of the file /adminapi/system/crontab/save of the comp… | |
| CVE-2026-82918 | MEDIUM | 5.5 | 2026-09-03 | XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity references. If a user opens a specially crafted setting fi… |