Search
78,493 CVEs
EOL hidden · Show all products
CVEs (78,493, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 78,493 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-11573 | NONE | — | 2026-09-08 | Uncontrolled recursion in Qt's QDomDocument serialization (QtXml) lets deeply nested untrusted XML crash the app via stack exhaustion (DoS only). | |
| CVE-2026-86714 | MEDIUM | 5.4 | 2026-09-08 | PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply… | |
| CVE-2026-86713 | HIGH | 7.1 | 2026-09-08 | PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module's stop path where exit_and_cleanup() deletes the LoadMon object and frees the pe… | |
| CVE-2026-86712 | HIGH | Patched | 8.8 | 2026-09-08 | SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled de… |
| CVE-2026-86711 | HIGH | Patched | 7.4 | 2026-09-08 | electerm before 5.3.15 exposes 40+ main-process functions through an unvalidated Electron IPC handler with no function-name allowlist or sender validation. Renderer-side sc… |
| CVE-2026-80219 | HIGH | 8.7 | 2026-09-08 | A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient with automatic grant approval (GrantMethod: au… | |
| CVE-2026-78234 | CRITICAL | 9.9 | 2026-09-08 | A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client cert… | |
| CVE-2026-77968 | HIGH | 8.2 | 2026-09-08 | A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controll… | |
| CVE-2026-76931 | MEDIUM | 6.4 | 2026-09-08 | The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 3.3.205 due t… | |
| CVE-2026-74860 | HIGH | 8.5 | 2026-09-08 | A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Docu… | |
| CVE-2026-3174 | HIGH | 7.5 | 2026-09-08 | The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endp… | |
| CVE-2026-2520 | MEDIUM | 5.4 | 2026-09-08 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t… | |
| CVE-2026-18021 | MEDIUM | 6.5 | 2026-09-08 | The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including… | |
| CVE-2026-17509 | MEDIUM | 6.5 | 2026-09-08 | The WPML Multilingual CMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘elementIds’ parameter in all versions up to, and including, 4.9.5 due to i… | |
| CVE-2026-16502 | HIGH | 8.8 | 2026-09-08 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 via deserializati… | |
| CVE-2026-12230 | MEDIUM | 6.4 | 2026-09-08 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout_custom_css' param… | |
| CVE-2026-77654 | NONE | — | 2026-09-08 | Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Inj… | |
| CVE-2026-19614 | NONE | — | 2026-09-08 | The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3. | |
| CVE-2026-9331 | HIGH | 7.1 | 2026-09-08 | The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing … | |
| CVE-2026-86590 | NONE | Patched | — | 2026-09-08 | In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP… |
| CVE-2026-85400 | NONE | — | 2026-09-08 | Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This al… | |
| CVE-2026-77132 | NONE | — | 2026-09-08 | It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged … | |
| CVE-2026-86597 | MEDIUM | 6.5 | 2026-09-08 | Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encrypti… | |
| CVE-2026-86550 | MEDIUM | 6.5 | 2026-09-08 | NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This resul… | |
| CVE-2026-74859 | MEDIUM | 6.8 | 2026-09-08 | The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files … |