Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 2,372 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86419 | NONE | — | 2026-09-07 | Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processin… | |
| CVE-2026-78325 | NONE | — | 2026-09-07 | Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the… | |
| CVE-2026-86351 | NONE | — | 2026-09-07 | Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /. That check is insufficient because protocol-rela… | |
| CVE-2026-82325 | NONE | — | 2026-09-07 | A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages | |
| CVE-2026-85201 | NONE | — | 2026-09-07 | In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Cont… | |
| CVE-2026-19204 | NONE | — | 2026-09-07 | A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exha… | |
| CVE-2026-86347 | NONE | — | 2026-09-07 | Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This … | |
| CVE-2026-84173 | NONE | — | 2026-09-07 | In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a… | |
| CVE-2026-86342 | NONE | — | 2026-09-07 | Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes fro… | |
| CVE-2026-84186 | NONE | — | 2026-09-07 | Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarde… | |
| CVE-2026-84732 | NONE | — | 2026-09-07 | Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a t… | |
| CVE-2026-14297 | NONE | — | 2026-09-07 | A buffer overflow in the Bluetooth Continuous Glucose Monitoring Service (CGMS) Record Access Control Point (RACP) write handler allows an authenticated BLE peer … | |
| CVE-2026-18796 | NONE | — | 2026-09-07 | Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally st… | |
| CVE-2026-81738 | NONE | — | 2026-09-07 | OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries | |
| CVE-2026-81830 | NONE | — | 2026-09-07 | The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file… | |
| CVE-2026-82312 | NONE | — | 2026-09-07 | OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on named IPC objects | |
| CVE-2026-84226 | NONE | — | 2026-09-07 | OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps | |
| CVE-2026-84256 | NONE | — | 2026-09-07 | An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a c… | |
| CVE-2026-78043 | NONE | — | 2026-09-07 | The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbit… | |
| CVE-2026-78221 | NONE | — | 2026-09-07 | An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or d… | |
| CVE-2026-78254 | NONE | Patched | — | 2026-09-07 | The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated t… |
| CVE-2026-20512 | NONE | — | 2026-09-07 | In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has alread… | |
| CVE-2026-16876 | NONE | — | 2026-09-07 | An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering… | |
| CVE-2026-86304 | NONE | Patched | — | 2026-09-06 | MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor. pars… |
| CVE-2026-86219 | NONE | Patched | — | 2026-09-06 | Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_start generates a fresh… |