Search
12,997 CVEs
CVEs (12,997, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 12,997 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-76161 | NONE | — | 2026-09-05 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-67277 | NONE | Patched | — | 2026-09-05 | RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start a… |
| CVE-2026-67278 | NONE | Patched | — | 2026-09-05 | MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirect… |
| CVE-2026-67279 | NONE | Patched | — | 2026-09-05 | RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a… |
| CVE-2026-67281 | NONE | Patched | — | 2026-09-05 | RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer use… |
| CVE-2026-86060 | NONE | Patched | — | 2026-09-05 | RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask … |
| CVE-2026-86206 | NONE | Patched | — | 2026-09-05 | A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4 |
| CVE-2026-67276 | NONE | Patched | — | 2026-09-05 | RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting … |
| CVE-2026-86207 | NONE | — | 2026-09-05 | An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs | |
| CVE-2026-82752 | NONE | Patched | — | 2026-09-05 | Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of arbitrary size in an attribute whose length const… |
| CVE-2026-86197 | NONE | Patched | — | 2026-09-05 | Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper ou… |
| CVE-2026-86193 | NONE | Patched | — | 2026-09-05 | grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts… |
| CVE-2026-86194 | NONE | Patched | — | 2026-09-05 | Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined on … |
| CVE-2026-86195 | NONE | Patched | — | 2026-09-05 | grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested supe… |
| CVE-2026-86196 | NONE | Patched | — | 2026-09-05 | Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redi… |
| CVE-2026-52777 | NONE | Patched | — | 2026-09-05 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This iss… |
| CVE-2026-52762 | NONE | Patched | — | 2026-09-05 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) vulnerability in the semantic templat… |
| CVE-2026-46636 | NONE | Patched | — | 2026-09-04 | Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instan… |
| CVE-2026-50894 | NONE | — | 2026-09-04 | easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to ex… | |
| CVE-2026-75438 | NONE | — | 2026-09-04 | Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function | |
| CVE-2026-75439 | NONE | — | 2026-09-04 | An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component | |
| CVE-2026-79423 | NONE | — | 2026-09-04 | An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request. | |
| CVE-2026-79426 | NONE | — | 2026-09-04 | An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafte… | |
| CVE-2025-67066 | NONE | — | 2026-09-04 | SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path | |
| CVE-2022-26961 | NONE | — | 2026-09-04 | Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the na… |