Search
565 CVEs · published 2026-09-24 to 2026-09-24
CVEs (565, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 565 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-48073 | MEDIUM | Patched | 4.3 | 2026-09-24 | Docmost is open-source collaborative wiki and documentation software. From 0.70.0 until 0.80.1, a low-privileged authenticated user who can edit an exportable page can embe… |
| CVE-2026-48072 | MEDIUM | Patched | 5.3 | 2026-09-24 | Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, the public avatar and logo image endpoint accepts attacker-controlled fileName path s… |
| CVE-2026-48070 | HIGH | Patched | 7.1 | 2026-09-24 | Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store attacker-controlled avatarUrl values that are later reu… |
| CVE-2026-13249 | CRITICAL | 9.8 | 2026-09-24 | An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040,… | |
| CVE-2026-13248 | HIGH | 8.8 | 2026-09-24 | An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD4… | |
| CVE-2026-13016 | NONE | Patched | — | 2026-09-24 | ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certa… |
| CVE-2026-97233 | LOW | 3.5 | 2026-09-24 | A vulnerability was identified in volotat Anagnorisis up to 0.4.11. Affected by this issue is the function html of the file PlaylistManager.js of the component Media Filena… | |
| CVE-2026-97232 | MEDIUM | 6.3 | 2026-09-24 | A vulnerability was determined in volotat Anagnorisis up to 0.4.2. Affected by this vulnerability is the function get_file_content/save_file_content/move_files/start_stream… | |
| CVE-2026-95985 | HIGH | Patched | 8.8 | 2026-09-24 | The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a use… |
| CVE-2026-93405 | MEDIUM | Patched | 6.1 | 2026-09-24 | Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markdown, DOCX, and XLSX attachments with Snarkdown, Mamm… |
| CVE-2026-91121 | MEDIUM | Patched | 5.0 | 2026-09-24 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, attacker-controlled upload filenames used in chat message excerpts wer… |
| CVE-2026-91120 | MEDIUM | Patched | 5.4 | 2026-09-24 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, provider-controlled video titles in lazy video embeds could be reparse… |
| CVE-2026-91119 | MEDIUM | Patched | 6.4 | 2026-09-24 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the topic small-action and nested-activity-log components interpolated… |
| CVE-2026-85057 | HIGH | Patched | 8.7 | 2026-09-24 | ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables the goja Node-compatible require() registry without r… |
| CVE-2026-85056 | HIGH | Patched | 8.2 | 2026-09-24 | ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1, ZITADEL Login V2 creates a browser session after password verification and can reuse that s… |
| CVE-2026-81508 | MEDIUM | 4.3 | 2026-09-24 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.5, 6.0.1, and 6.1, the BlueDroid A2DP sink function btc_a2dp_sink_handle_inc_media() reads a… | |
| CVE-2026-71540 | HIGH | Patched | 7.5 | 2026-09-24 | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.9.0 until 4.14.7, wazuh-clusterd in framework/… |
| CVE-2026-63645 | HIGH | Patched | 7.5 | 2026-09-24 | OpenObserve is a cloud-native observability platform. Prior to 0.90.3, OpenObserve registers the /config/runtime endpoint without authentication and serializes the complete… |
| CVE-2026-61816 | HIGH | Patched | 7.5 | 2026-09-24 | zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Starting in… |
| CVE-2026-61815 | HIGH | Patched | 7.2 | 2026-09-24 | zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Prior to ve… |
| CVE-2026-61811 | MEDIUM | Patched | 6.5 | 2026-09-24 | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.8.0 until 4.14.7, the _getattributes() functio… |
| CVE-2026-61788 | HIGH | 7.4 | 2026-09-24 | DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Prior to version 0.22.6, setting `readonly = true` on the `execute_sql` tool does n… | |
| CVE-2026-61784 | MEDIUM | 6.1 | 2026-09-24 | xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, trusted HTML. Versions prior to 0.4.3 do not HTML-entity-encode attr… | |
| CVE-2026-61782 | HIGH | 7.5 | 2026-09-24 | Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to version 1.5.16, the default Rsdoctor report HTTP server started by `@rsdoctor/rspack-plugin` … | |
| CVE-2026-61742 | NONE | — | 2026-09-24 | DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose an unauthenticated HTTP MCP endpoint when started w… |