Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

78,493 CVEs

EOL hidden · Show all products

CVEs (78,493, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 76–100 of 78,493 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-11573 NONE — 2026-09-08 Uncontrolled recursion in Qt's QDomDocument serialization (QtXml) lets deeply nested untrusted XML crash the app via stack exhaustion (DoS only).
CVE-2026-86714 MEDIUM 5.4 2026-09-08 PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply…
CVE-2026-86713 HIGH 7.1 2026-09-08 PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module's stop path where exit_and_cleanup() deletes the LoadMon object and frees the pe…
CVE-2026-86712 HIGH Patched 8.8 2026-09-08 SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled de…
CVE-2026-86711 HIGH Patched 7.4 2026-09-08 electerm before 5.3.15 exposes 40+ main-process functions through an unvalidated Electron IPC handler with no function-name allowlist or sender validation. Renderer-side sc…
CVE-2026-80219 HIGH 8.7 2026-09-08 A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient with automatic grant approval (GrantMethod: au…
CVE-2026-78234 CRITICAL 9.9 2026-09-08 A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client cert…
CVE-2026-77968 HIGH 8.2 2026-09-08 A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controll…
CVE-2026-76931 MEDIUM 6.4 2026-09-08 The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 3.3.205 due t…
CVE-2026-74860 HIGH 8.5 2026-09-08 A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Docu…
CVE-2026-3174 HIGH 7.5 2026-09-08 The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endp…
CVE-2026-2520 MEDIUM 5.4 2026-09-08 The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t…
CVE-2026-18021 MEDIUM 6.5 2026-09-08 The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including…
CVE-2026-17509 MEDIUM 6.5 2026-09-08 The WPML Multilingual CMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘elementIds’ parameter in all versions up to, and including, 4.9.5 due to i…
CVE-2026-16502 HIGH 8.8 2026-09-08 The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 via deserializati…
CVE-2026-12230 MEDIUM 6.4 2026-09-08 The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout_custom_css' param…
CVE-2026-77654 NONE — 2026-09-08 Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Inj…
CVE-2026-19614 NONE — 2026-09-08 The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3.
CVE-2026-9331 HIGH 7.1 2026-09-08 The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing …
CVE-2026-86590 NONE Patched — 2026-09-08 In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP…
CVE-2026-85400 NONE — 2026-09-08 Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This al…
CVE-2026-77132 NONE — 2026-09-08 It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged …
CVE-2026-86597 MEDIUM 6.5 2026-09-08 Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encrypti…
CVE-2026-86550 MEDIUM 6.5 2026-09-08 NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This resul…
CVE-2026-74859 MEDIUM 6.8 2026-09-08 The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files …