Search
565 CVEs · published 2026-09-24 to 2026-09-24
CVEs (565, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 51–75 of 565 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-96749 | HIGH | 8.4 | 2026-09-24 | An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusua… | |
| CVE-2026-96748 | MEDIUM | 6.5 | 2026-09-24 | PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a… | |
| CVE-2026-96747 | MEDIUM | 5.0 | 2026-09-24 | The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path r… | |
| CVE-2026-89325 | HIGH | Patched | 7.8 | 2026-09-24 | An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYST… |
| CVE-2026-86860 | NONE | Patched | — | 2026-09-24 | ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, … |
| CVE-2026-86859 | NONE | Patched | — | 2026-09-24 | ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unaut… |
| CVE-2026-86858 | NONE | Patched | — | 2026-09-24 | ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated u… |
| CVE-2026-86857 | NONE | Patched | — | 2026-09-24 | ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authe… |
| CVE-2026-85738 | MEDIUM | Patched | 6.3 | 2026-09-24 | TREK is a collaborative travel planner. Prior to 3.4.0, the checkSsrf logic in server/src/utils/ssrfGuard.ts does not recognize NAT64, 6to4, or Teredo IPv6 transition addre… |
| CVE-2026-82371 | NONE | Patched | — | 2026-09-24 | Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals with file read access to retrieve administrative switc… |
| CVE-2026-82157 | HIGH | 8.3 | 2026-09-24 | Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent netwo… | |
| CVE-2026-81473 | HIGH | 8.1 | 2026-09-24 | Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially … | |
| CVE-2026-81455 | HIGH | 8.6 | 2026-09-24 | Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with rem… | |
| CVE-2026-77321 | MEDIUM | Patched | 4.3 | 2026-09-24 | TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_summary tool in server/src/mcp/tools/trips.ts is registered for scoped OAuth MCP tokens without requiri… |
| CVE-2026-77320 | MEDIUM | Patched | 5.3 | 2026-09-24 | TREK is a collaborative travel planner. Prior to 3.3.0, getSharedTripData in server/src/services/shareService.ts returns days, assignments, dayNotes, and places through GET… |
| CVE-2026-77294 | HIGH | Patched | 8.1 | 2026-09-24 | TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url through the settings API when the LLM… |
| CVE-2026-77293 | HIGH | Patched | 7.1 | 2026-09-24 | TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId endpoint authorizes an authenticated user against t… |
| CVE-2026-65827 | MEDIUM | Patched | 6.5 | 2026-09-24 | Docmost is open-source collaborative wiki and documentation software. From 0.21.0 until 0.95.0, any authenticated workspace member with edit rights to a space can upload an… |
| CVE-2026-62286 | MEDIUM | Patched | 4.3 | 2026-09-24 | Dozzle is a realtime log viewer for docker containers. Prior to 10.6.7, streamEvents in internal/web/events.go applies a restricted user's label filter to container lists b… |
| CVE-2026-61825 | HIGH | Patched | 8.7 | 2026-09-24 | code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulner… |
| CVE-2026-61823 | HIGH | Patched | 7.3 | 2026-09-24 | code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulner… |
| CVE-2026-57440 | HIGH | 7.5 | 2026-09-24 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing servi… | |
| CVE-2026-56792 | MEDIUM | 4.4 | 2026-09-24 | Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially … | |
| CVE-2026-52853 | MEDIUM | Patched | 5.2 | 2026-09-24 | Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace ADMIN can use the workspace invitation flow to invite an e… |
| CVE-2026-52850 | MEDIUM | Patched | 4.3 | 2026-09-24 | Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace member who does not belong to a private space can call the… |