Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,126 CVEs

CVEs (30,126, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 51–75 of 30,126 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-81830 NONE — 2026-09-07 The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file…
CVE-2026-82312 NONE — 2026-09-07 OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on named IPC objects
CVE-2026-84226 NONE — 2026-09-07 OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps
CVE-2026-84256 NONE — 2026-09-07 An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a c…
CVE-2026-78043 NONE — 2026-09-07 The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbit…
CVE-2026-78221 NONE — 2026-09-07 An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or d…
CVE-2026-78254 NONE Patched — 2026-09-07 The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated t…
CVE-2026-20512 NONE — 2026-09-07 In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has alread…
CVE-2026-16876 NONE — 2026-09-07 An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering…
CVE-2026-86304 NONE Patched — 2026-09-06 MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor. pars…
CVE-2026-86219 NONE Patched — 2026-09-06 Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_start generates a fresh…
CVE-2026-80229 NONE — 2026-09-06 When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl at…
CVE-2026-80230 NONE — 2026-09-06 When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libc…
CVE-2026-80231 NONE — 2026-09-06 A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`…
CVE-2026-80255 NONE — 2026-09-06 A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie w…
CVE-2026-82208 NONE — 2026-09-06 With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store af…
CVE-2026-82209 NONE — 2026-09-06 When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly…
CVE-2026-18924 NONE — 2026-09-06 A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup…
CVE-2026-19931 NONE — 2026-09-06 A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credenti…
CVE-2026-13608 NONE — 2026-09-06 A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An a…
CVE-2026-82751 NONE Patched — 2026-09-06 Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a lar…
CVE-2026-82750 NONE Patched — 2026-09-06 Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a lar…
CVE-2026-86283 NONE — 2026-09-06 MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access …
CVE-2026-86218 NONE Patched — 2026-09-06 N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
CVE-2026-76160 NONE — 2026-09-05 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.