Search
565 CVEs · published 2026-09-24 to 2026-09-24
CVEs (565, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 565 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-17503 | MEDIUM | 5.1 | 2026-09-24 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability i… | |
| CVE-2026-17413 | MEDIUM | 5.1 | 2026-09-24 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability i… | |
| CVE-2026-97182 | HIGH | 7.3 | 2026-09-24 | A security vulnerability has been detected in halo-dev Halo up to 2.25.4/2.26.1. Affected is an unknown function of the file application/src/main/java/run/halo/app/content/… | |
| CVE-2026-96515 | NONE | — | 2026-09-24 | This vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input validation controls in the diagnostic script import functionality. A… | |
| CVE-2026-94416 | MEDIUM | 6.8 | 2026-09-24 | An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for th… | |
| CVE-2026-88916 | MEDIUM | 6.8 | 2026-09-24 | Incorrect Authorization vulnerability in TÜBİTAK ULAKBİM UlakPDF allows Privilege Escalation. This issue affects UlakPDF: through 09092026. | |
| CVE-2026-88907 | HIGH | 7.4 | 2026-09-24 | Incorrect Authorization vulnerability in TÜBİTAK ULAKBİM UlakPDF allows Authentication Bypass. This issue affects UlakPDF: through 09092026. | |
| CVE-2026-19072 | CRITICAL | 9.9 | 2026-09-24 | Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_co… | |
| CVE-2026-97311 | MEDIUM | 4.3 | 2026-09-24 | A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with a specific role do not… | |
| CVE-2026-7169 | NONE | — | 2026-09-24 | a vulnerability involving an unchecked search path element in Evope Collector, versions prior to 1.1.7.13, allows a local attacker without privileges to load a malicious DL… | |
| CVE-2026-4806 | MEDIUM | 6.5 | 2026-09-24 | The Custom Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the save_option() … | |
| CVE-2026-3253 | MEDIUM | 4.3 | 2026-09-24 | The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the forms() method of … | |
| CVE-2026-19532 | MEDIUM | Patched | 5.3 | 2026-09-24 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HAVELSAN Inc. Liman MYS allows Path Traversal. This issue affects Liman MYS… |
| CVE-2026-16302 | MEDIUM | 4.3 | 2026-09-24 | The Spectra Legacy – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0 via the editor_asset… | |
| CVE-2026-97179 | MEDIUM | 4.3 | 2026-09-24 | A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2. This vulnerability affects the function list of the file o2server/x_base_core_project/src/main/java/c… | |
| CVE-2026-79680 | NONE | — | 2026-09-24 | Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker using a specially modified VNC client that violates th… | |
| CVE-2026-4638 | NONE | — | 2026-09-24 | PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer parameters using cscript.exe. If a non-numeric value is passed … | |
| CVE-2026-92905 | MEDIUM | 5.3 | 2026-09-24 | ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a DoS vulnerability that allowed attackers to crash the log collector using malform… | |
| CVE-2026-57590 | HIGH | Patched | 8.1 | 2026-09-24 | A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has … |
| CVE-2026-4637 | NONE | — | 2026-09-24 | Paessler PRTG Network Monitor before version 26.2.120.1449 is affected by a reflected Cross-Site Scripting (XSS) vulnerability. When a request is made for a non-existent re… | |
| CVE-2026-18335 | MEDIUM | 5.4 | 2026-09-24 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including… | |
| CVE-2026-15731 | MEDIUM | 6.4 | 2026-09-24 | The WP Multilang – Translation and Multilingual Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post content in all versions up to, and inc… | |
| CVE-2026-12227 | CRITICAL | 9.8 | 2026-09-24 | The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` paramete… | |
| CVE-2026-97185 | HIGH | 7.8 | 2026-09-24 | A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-si… | |
| CVE-2026-85682 | HIGH | 8.8 | 2026-09-24 | The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest no… |