Search
12,997 CVEs
CVEs (12,997, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 12,997 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-44766 | MEDIUM | 6.5 | 2026-09-08 | SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed b… | |
| CVE-2026-44756 | CRITICAL | 10.0 | 2026-09-08 | A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a craf… | |
| CVE-2026-86544 | HIGH | Patched | 8.1 | 2026-09-07 | knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with r… |
| CVE-2026-86543 | CRITICAL | Patched | 9.8 | 2026-09-07 | knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attack… |
| CVE-2026-86542 | CRITICAL | Patched | 9.1 | 2026-09-07 | knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can sup… |
| CVE-2026-86541 | HIGH | Patched | 8.3 | 2026-09-07 | knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the proj… |
| CVE-2026-86540 | HIGH | Patched | 7.8 | 2026-09-07 | knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by c… |
| CVE-2026-86539 | HIGH | 7.2 | 2026-09-07 | knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied … | |
| CVE-2026-86538 | HIGH | Patched | 7.5 | 2026-09-07 | knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary fil… |
| CVE-2026-86439 | HIGH | Patched | 8.8 | 2026-09-07 | knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project di… |
| CVE-2026-82758 | NONE | Patched | — | 2026-09-07 | Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client … |
| CVE-2026-82757 | NONE | Patched | — | 2026-09-07 | Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make t… |
| CVE-2026-82756 | NONE | Patched | — | 2026-09-07 | Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication … |
| CVE-2026-82755 | NONE | Patched | — | 2026-09-07 | Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant's OAuth discovery… |
| CVE-2026-82754 | NONE | Patched | — | 2026-09-07 | Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefi… |
| CVE-2026-82753 | NONE | Patched | — | 2026-09-07 | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to exhaust database st… |
| CVE-2026-82586 | NONE | Patched | — | 2026-09-07 | Improper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list… |
| CVE-2026-82584 | NONE | Patched | — | 2026-09-07 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project igniter allows a malicious package publisher to forge the mix igniter.install con… |
| CVE-2026-81638 | NONE | Patched | — | 2026-09-07 | Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.… |
| CVE-2026-86438 | HIGH | Patched | 7.2 | 2026-09-07 | Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attack… |
| CVE-2026-86437 | HIGH | Patched | 7.2 | 2026-09-07 | Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators… |
| CVE-2026-86436 | MEDIUM | Patched | 5.4 | 2026-09-07 | Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to u… |
| CVE-2026-75650 | CRITICAL | 10.0 | 2026-09-07 | Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the co… | |
| CVE-2026-86287 | NONE | Patched | — | 2026-09-07 | Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths. Non-numeric and non-ASCII prefix lengths are accepted and treated as 0. Integers over 31 bits a… |
| CVE-2026-16028 | NONE | Patched | — | 2026-09-07 | Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table. When a stream re… |