Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

565 CVEs · published 2026-09-24 to 2026-09-24

CVEs (565, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 51–75 of 565 (capped at 500)

CVE ID Severity Patch CVSS Published ↓ Description
CVE-2026-96749 HIGH 8.4 2026-09-24 An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusua…
CVE-2026-96748 MEDIUM 6.5 2026-09-24 PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a…
CVE-2026-96747 MEDIUM 5.0 2026-09-24 The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path r…
CVE-2026-89325 HIGH Patched 7.8 2026-09-24 An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYST…
CVE-2026-86860 NONE Patched — 2026-09-24 ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, …
CVE-2026-86859 NONE Patched — 2026-09-24 ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unaut…
CVE-2026-86858 NONE Patched — 2026-09-24 ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated u…
CVE-2026-86857 NONE Patched — 2026-09-24 ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authe…
CVE-2026-85738 MEDIUM Patched 6.3 2026-09-24 TREK is a collaborative travel planner. Prior to 3.4.0, the checkSsrf logic in server/src/utils/ssrfGuard.ts does not recognize NAT64, 6to4, or Teredo IPv6 transition addre…
CVE-2026-82371 NONE Patched — 2026-09-24 Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals with file read access to retrieve administrative switc…
CVE-2026-82157 HIGH 8.3 2026-09-24 Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent netwo…
CVE-2026-81473 HIGH 8.1 2026-09-24 Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially …
CVE-2026-81455 HIGH 8.6 2026-09-24 Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with rem…
CVE-2026-77321 MEDIUM Patched 4.3 2026-09-24 TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_summary tool in server/src/mcp/tools/trips.ts is registered for scoped OAuth MCP tokens without requiri…
CVE-2026-77320 MEDIUM Patched 5.3 2026-09-24 TREK is a collaborative travel planner. Prior to 3.3.0, getSharedTripData in server/src/services/shareService.ts returns days, assignments, dayNotes, and places through GET…
CVE-2026-77294 HIGH Patched 8.1 2026-09-24 TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url through the settings API when the LLM…
CVE-2026-77293 HIGH Patched 7.1 2026-09-24 TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId endpoint authorizes an authenticated user against t…
CVE-2026-65827 MEDIUM Patched 6.5 2026-09-24 Docmost is open-source collaborative wiki and documentation software. From 0.21.0 until 0.95.0, any authenticated workspace member with edit rights to a space can upload an…
CVE-2026-62286 MEDIUM Patched 4.3 2026-09-24 Dozzle is a realtime log viewer for docker containers. Prior to 10.6.7, streamEvents in internal/web/events.go applies a restricted user's label filter to container lists b…
CVE-2026-61825 HIGH Patched 8.7 2026-09-24 code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulner…
CVE-2026-61823 HIGH Patched 7.3 2026-09-24 code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulner…
CVE-2026-57440 HIGH 7.5 2026-09-24 The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing servi…
CVE-2026-56792 MEDIUM 4.4 2026-09-24 Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially …
CVE-2026-52853 MEDIUM Patched 5.2 2026-09-24 Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace ADMIN can use the workspace invitation flow to invite an e…
CVE-2026-52850 MEDIUM Patched 4.3 2026-09-24 Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace member who does not belong to a private space can call the…