Search
2,281 CVEs
CVEs (2,281, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 2,281 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-83595 | HIGH | 8.1 | 2026-09-01 | AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform state-changing actions by crafting GET requests that … | |
| CVE-2026-84187 | HIGH | 8.2 | 2026-09-01 | AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticated attackers to mark arbitrary scheduled broadcasts as failed … | |
| CVE-2026-84188 | MEDIUM | Patched | 4.8 | 2026-09-01 | LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.<graphtype> configuration settings, which are echoed verbatim without HTM… |
| CVE-2026-84189 | HIGH | Patched | 8.1 | 2026-09-01 | LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the de… |
| CVE-2026-84190 | HIGH | Patched | 7.2 | 2026-09-01 | LibreNMS versions before 26.5.0 contain a remote code execution vulnerability in the AboutController where the snmpget configuration parameter is passed to shell_exec() wit… |
| CVE-2026-84191 | MEDIUM | Patched | 6.1 | 2026-09-01 | LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages where mplsVpnVrfDescription, vrf_name, and mplsVpnVrfRouteDistinguisher fie… |
| CVE-2026-84192 | HIGH | Patched | 7.1 | 2026-09-01 | LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without escaping. An at… |
| CVE-2026-84193 | NONE | — | 2026-09-01 | LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer … | |
| CVE-2026-84194 | NONE | Patched | — | 2026-09-01 | LibreNMS versions >= 23.10.0 and < 26.2.0 (fixed in 26.4.0) contain an authenticated OS command injection vulnerability in libvirt discovery. When libvirt support is enable… |
| CVE-2026-84195 | HIGH | Patched | 7.7 | 2026-09-01 | Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorizatio… |
| CVE-2026-84196 | HIGH | Patched | 7.7 | 2026-09-01 | Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecti… |
| CVE-2026-84199 | HIGH | Patched | 7.7 | 2026-09-01 | Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not valid… |
| CVE-2026-84200 | CRITICAL | Patched | 9.0 | 2026-09-01 | Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive … |
| CVE-2026-18765 | CRITICAL | 9.8 | 2026-09-01 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This … | |
| CVE-2026-19471 | NONE | — | 2026-09-01 | Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, a… | |
| CVE-2026-19472 | NONE | — | 2026-09-01 | A denial-of-service security issue exists within ArmorStart® LT. The security issue stems from improper handling of a crafted HTTP PUT request sent to the embedded web serv… | |
| CVE-2026-51741 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a craft… | |
| CVE-2026-51742 | MEDIUM | 5.9 | 2026-09-01 | Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger WAN discovery logic via sending a craf… | |
| CVE-2026-51743 | CRITICAL | 9.1 | 2026-09-01 | Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via se… | |
| CVE-2026-51744 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronizati… | |
| CVE-2026-51745 | MEDIUM | 5.3 | 2026-09-01 | Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the primary station list via send… | |
| CVE-2026-51747 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh heartbeat information toward … | |
| CVE-2026-53682 | MEDIUM | 5.3 | 2026-09-01 | An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA … | |
| CVE-2026-58575 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges t… | |
| CVE-2026-79683 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write a… |