Search
163,207 CVEs · Medium severity
EOL hidden · Show all products
CVEs (163,207, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 163,207 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2022-51015 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP before 4.0.6 does not validate facing values in PlayerActionPacket (for START_BREAK and CRACK_BREAK actions) or in UseItemTransactionData (typically within In… |
| CVE-2022-51014 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP before 4.0.7 contains an unhandled exception vulnerability in the ModalFormResponsePacket handler when processing malformed JSON from clients. Attackers can s… |
| CVE-2022-51013 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data received from clients. Attackers can send negative or out-of-ran… |
| CVE-2022-51012 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafte… |
| CVE-2022-51011 | MEDIUM | Patched | 4.3 | 2026-09-07 | PocketMine-MP before 4.2.10 fails to validate the total length of incoming chat message blobs before splitting them by newline characters, allowing attackers to send large … |
| CVE-2022-51010 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP versions before 4.4.2 fail to properly validate item IDs received from clients in itemstack NBT data. Attackers can send crafted item IDs outside the valid ra… |
| CVE-2026-2390 | MEDIUM | 6.4 | 2026-09-07 | The Powerkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lazy Load module's image processing in all versions up to, and including, 3.0.4. This… | |
| CVE-2026-86294 | MEDIUM | 4.3 | 2026-09-07 | A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of th… | |
| CVE-2026-85640 | MEDIUM | 6.3 | 2026-09-07 | Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component | |
| CVE-2026-77699 | MEDIUM | 5.0 | 2026-09-07 | Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path. | |
| CVE-2026-77697 | MEDIUM | 6.3 | 2026-09-07 | Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction | |
| CVE-2026-86293 | MEDIUM | 6.5 | 2026-09-07 | A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown functionality of the file delete-user.php of the com… | |
| CVE-2026-86291 | MEDIUM | 6.3 | 2026-09-07 | A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/us_edit1.php. Such manipulati… | |
| CVE-2026-77698 | MEDIUM | Patched | 5.7 | 2026-09-07 | Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade. |
| CVE-2026-86332 | MEDIUM | 6.5 | 2026-09-07 | A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard ser… | |
| CVE-2026-86289 | MEDIUM | 4.3 | 2026-09-07 | A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing a m… | |
| CVE-2026-86288 | MEDIUM | 6.3 | 2026-09-07 | A vulnerability has been found in ModelCloud GPTQModel up to 7.2.0. This vulnerability affects unknown code of the file gptqmodel/nn_modules/qlinear/tritonv2.py of the comp… | |
| CVE-2026-86285 | MEDIUM | 4.3 | 2026-09-07 | A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/Atta… | |
| CVE-2026-86284 | MEDIUM | 5.3 | 2026-09-07 | A security vulnerability has been detected in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected by this vulnerability is the… | |
| CVE-2026-86281 | MEDIUM | 4.3 | 2026-09-07 | A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This impacts an unknown function. Performing a manipula… | |
| CVE-2026-86280 | MEDIUM | 5.3 | 2026-09-07 | A vulnerability was identified in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This affects an unknown function of the file cict_portal.sql… | |
| CVE-2026-86279 | MEDIUM | 6.3 | 2026-09-07 | A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The impacted element is an unknown function of the file auth… | |
| CVE-2026-86278 | MEDIUM | 4.3 | 2026-09-07 | A vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file manage_su… | |
| CVE-2026-86275 | MEDIUM | 5.3 | 2026-09-07 | A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerability affects the function register of the file a… | |
| CVE-2026-86274 | MEDIUM | 5.3 | 2026-09-07 | A security vulnerability has been detected in projeto-siga siga up to 11.0.2.10/11.0.2.13/11.1.1. This affects the function ExAutenticacaoController.autenticar of the file … |