Search
790 CVEs · Medium severity
CVEs (790, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 790 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-85092 | MEDIUM | 6.6 | 2026-09-03 | LiME through 1.12.0 fails to validate the disk acquisition output path and does not use O_NOFOLLOW when opening the operator-supplied path parameter, allowing unprivileged … | |
| CVE-2026-85090 | MEDIUM | Patched | 5.4 | 2026-09-03 | FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP s… |
| CVE-2026-85089 | MEDIUM | Patched | 6.5 | 2026-09-03 | FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/c… |
| CVE-2026-85084 | MEDIUM | 6.3 | 2026-09-03 | Out-of-bounds Write and Improper Validation of Array Index vulnerability in Samsung Open Source TizenFX Samsung/TizenFX allows Overflow Buffers. | |
| CVE-2026-85040 | MEDIUM | 4.7 | 2026-09-03 | A weakness has been identified in ZhongBangKeJi CRMEB up to 6.0.0. Affected by this vulnerability is the function eval of the file /adminapi/system/crontab/save of the comp… | |
| CVE-2026-85021 | MEDIUM | 4.3 | 2026-09-03 | A vulnerability was determined in langgenius dify 1.13.0. Affected is the function router.replace of the file web/app/(shareLayout)/components/splash.tsx of the component S… | |
| CVE-2026-82918 | MEDIUM | 5.5 | 2026-09-03 | XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity references. If a user opens a specially crafted setting fi… | |
| CVE-2026-80254 | MEDIUM | 6.5 | 2026-09-03 | Authorization bypass through user-controlled key issue exists in ShizenBox2 (edge-app). If exploited, an attacker who can log in to the product may change the other user's … | |
| CVE-2026-80253 | MEDIUM | 6.8 | 2026-09-03 | An improper physical access control issue exists in ShizenBox2 (dev-conf). If exploited, an attacker with physical access to the product may execute bootloader commands wit… | |
| CVE-2026-74769 | MEDIUM | 6.5 | 2026-09-03 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API. A low privileged remote attacker could potent… | |
| CVE-2026-74768 | MEDIUM | 4.1 | 2026-09-03 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability in the REST API. A high privileged remote attacker c… | |
| CVE-2026-71224 | MEDIUM | 4.7 | 2026-09-03 | A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata withou… | |
| CVE-2026-71222 | MEDIUM | 5.3 | 2026-09-03 | A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causi… | |
| CVE-2026-71219 | MEDIUM | 4.7 | 2026-09-03 | A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-d… | |
| CVE-2026-68860 | MEDIUM | 6.8 | 2026-09-03 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulnerability. An unauthenticated remote attacker could potentially ex… | |
| CVE-2026-3852 | MEDIUM | 6.4 | 2026-09-03 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `skype_url` shortcode attribute of the Social Media Follow module in all versions up to, a… | |
| CVE-2026-3416 | MEDIUM | 5.9 | 2026-09-03 | The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks s… | |
| CVE-2026-2573 | MEDIUM | 6.4 | 2026-09-03 | The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘postBodyCs… | |
| CVE-2026-17539 | MEDIUM | 5.9 | 2026-09-03 | RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry of the enhance… | |
| CVE-2021-43614 | MEDIUM | 6.7 | 2026-09-03 | Error in handling the PlatformLangCodes UEFI variable could cause a buffer overflow, leading to resource exhaustion and failure. | |
| CVE-2021-43613 | MEDIUM | 6.5 | 2026-09-03 | An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User and administrator password hashes are exposed in runtime UEFI variables, leading to escalation of privilege | |
| CVE-2026-84888 | MEDIUM | 4.3 | 2026-09-03 | A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. This vulnerability affects the function shell_exec of the file crates/openfang-runtime/src/tool_runner.r… | |
| CVE-2026-84887 | MEDIUM | 4.3 | 2026-09-03 | A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affected by this issue is some unknown functionality of the file grounding.py of the component Model-gener… | |
| CVE-2026-84886 | MEDIUM | 5.3 | 2026-09-03 | A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affected by this vulnerability is the function ImageData of the file gui_agents/s1/utils/ocr_server.py of … | |
| CVE-2026-84885 | MEDIUM | 4.3 | 2026-09-03 | A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This impacts an unknown function of the file code_agent.py of the component CodeAgent. Such manipulation l… |