Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,107 CVEs

EOL hidden · Show all products

CVEs (30,107, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 76–100 of 30,107 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-44766 MEDIUM 6.5 2026-09-08 SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed b…
CVE-2026-44756 CRITICAL 10.0 2026-09-08 A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a craf…
CVE-2026-86544 HIGH Patched 8.1 2026-09-07 knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with r…
CVE-2026-86543 CRITICAL Patched 9.8 2026-09-07 knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attack…
CVE-2026-86542 CRITICAL Patched 9.1 2026-09-07 knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can sup…
CVE-2026-86541 HIGH Patched 8.3 2026-09-07 knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the proj…
CVE-2026-86540 HIGH Patched 7.8 2026-09-07 knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by c…
CVE-2026-86539 HIGH 7.2 2026-09-07 knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied …
CVE-2026-86538 HIGH Patched 7.5 2026-09-07 knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary fil…
CVE-2026-86439 HIGH Patched 8.8 2026-09-07 knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project di…
CVE-2026-82758 NONE Patched — 2026-09-07 Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client …
CVE-2026-82757 NONE Patched — 2026-09-07 Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make t…
CVE-2026-82756 NONE Patched — 2026-09-07 Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication …
CVE-2026-82755 NONE Patched — 2026-09-07 Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant's OAuth discovery…
CVE-2026-82754 NONE Patched — 2026-09-07 Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefi…
CVE-2026-82753 NONE Patched — 2026-09-07 Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to exhaust database st…
CVE-2026-82586 NONE Patched — 2026-09-07 Improper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list…
CVE-2026-82584 NONE Patched — 2026-09-07 Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project igniter allows a malicious package publisher to forge the mix igniter.install con…
CVE-2026-81638 NONE Patched — 2026-09-07 Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.…
CVE-2026-86438 HIGH Patched 7.2 2026-09-07 Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attack…
CVE-2026-86437 HIGH Patched 7.2 2026-09-07 Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators…
CVE-2026-86436 MEDIUM Patched 5.4 2026-09-07 Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to u…
CVE-2026-75650 CRITICAL 10.0 2026-09-07 Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the co…
CVE-2026-86287 NONE Patched — 2026-09-07 Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths. Non-numeric and non-ASCII prefix lengths are accepted and treated as 0. Integers over 31 bits a…
CVE-2026-16028 NONE Patched — 2026-09-07 Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table. When a stream re…