Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,217 CVEs

CVEs (30,217, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 51–75 of 30,217 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-12962 NONE — 2026-09-08 A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a …
CVE-2026-16003 NONE — 2026-09-08 Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IO…
CVE-2026-16004 NONE — 2026-09-08 Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL reques…
CVE-2026-16005 NONE — 2026-09-08 Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verificat…
CVE-2026-16006 NONE — 2026-09-08 Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCT…
CVE-2026-82710 NONE Patched — 2026-09-08 Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control seque…
CVE-2026-82758 NONE Patched — 2026-09-07 Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client …
CVE-2026-82586 NONE Patched — 2026-09-07 Improper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list…
CVE-2026-82753 NONE Patched — 2026-09-07 Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to exhaust database st…
CVE-2026-82754 NONE Patched — 2026-09-07 Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefi…
CVE-2026-82755 NONE Patched — 2026-09-07 Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant's OAuth discovery…
CVE-2026-82756 NONE Patched — 2026-09-07 Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication …
CVE-2026-82757 NONE Patched — 2026-09-07 Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make t…
CVE-2026-81638 NONE Patched — 2026-09-07 Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.…
CVE-2026-82584 NONE Patched — 2026-09-07 Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project igniter allows a malicious package publisher to forge the mix igniter.install con…
CVE-2026-86287 NONE Patched — 2026-09-07 Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths. Non-numeric and non-ASCII prefix lengths are accepted and treated as 0. Integers over 31 bits a…
CVE-2026-16028 NONE Patched — 2026-09-07 Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table. When a stream re…
CVE-2026-86452 NONE — 2026-09-07 Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/…
CVE-2026-86440 NONE — 2026-09-07 Affected versions of MISP insufficiently validate URLs used by dashboard widgets, particularly the Button widget. The widget's URL is stored configuration controlled by a…
CVE-2026-86441 NONE — 2026-09-07 Affected versions of MISP contain inconsistent authorization checks across dashboard widgets that display organisation information. Several organisation-related widgets d…
CVE-2026-86451 NONE — 2026-09-07 Affected versions of MISP allow authenticated users to retrieve object-reference records by UUID through EventGraphTool::get_reference_data() without first checking whether…
CVE-2026-86426 NONE Patched — 2026-09-07 LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeri…
CVE-2026-86408 NONE — 2026-09-07 Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queri…
CVE-2026-86417 NONE — 2026-09-07 Affected versions of MISP inconsistently enforced email-address visibility in DashboardsController::listTemplates(). The query always fetched User.email, while redaction …
CVE-2026-86418 NONE — 2026-09-07 Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal or…