Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 101–125 of 2,372 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86423 | LOW | Patched | 3.3 | 2026-09-07 | ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick. A crafted call to the GetList metho… |
| CVE-2026-86422 | LOW | Patched | 3.3 | 2026-09-07 | ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restricti… |
| CVE-2026-86421 | LOW | Patched | 3.7 | 2026-09-07 | ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allow… |
| CVE-2026-86420 | LOW | Patched | 3.7 | 2026-09-07 | ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can … |
| CVE-2026-86419 | NONE | — | 2026-09-07 | Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processin… | |
| CVE-2026-86418 | NONE | — | 2026-09-07 | Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal or… | |
| CVE-2026-86417 | NONE | — | 2026-09-07 | Affected versions of MISP inconsistently enforced email-address visibility in DashboardsController::listTemplates(). The query always fetched User.email, while redaction … | |
| CVE-2026-86416 | MEDIUM | Patched | 5.4 | 2026-09-07 | ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform… |
| CVE-2026-86408 | NONE | — | 2026-09-07 | Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queri… | |
| CVE-2026-86404 | HIGH | 8.8 | 2026-09-07 | EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list… | |
| CVE-2026-86351 | NONE | — | 2026-09-07 | Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /. That check is insufficient because protocol-rela… | |
| CVE-2026-86347 | NONE | — | 2026-09-07 | Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This … | |
| CVE-2026-86342 | NONE | — | 2026-09-07 | Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes fro… | |
| CVE-2026-86332 | MEDIUM | 6.5 | 2026-09-07 | A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard ser… | |
| CVE-2026-86321 | MEDIUM | 5.3 | 2026-09-07 | A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jacks… | |
| CVE-2026-86319 | MEDIUM | 5.3 | 2026-09-07 | A vulnerability has been found in java-json-tools json-patch up to 1.13. Affected by this vulnerability is the function JsonPatch.apply of the file src/main/java/com/github… | |
| CVE-2026-86318 | MEDIUM | 5.3 | 2026-09-07 | A flaw has been found in java-json-tools json-patch up to 1.13. Affected is the function JsonMergePatch.fromJson of the file JsonMergePatchDeserializer.java. Executing a ma… | |
| CVE-2026-86317 | MEDIUM | 5.3 | 2026-09-07 | A vulnerability was detected in ggml-org llama.cpp up to 0.4.0. This impacts the function rpc_server::deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the c… | |
| CVE-2026-86315 | MEDIUM | 6.2 | 2026-09-07 | An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt nati… | |
| CVE-2026-86314 | MEDIUM | 6.2 | 2026-09-07 | Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds… | |
| CVE-2026-86313 | HIGH | 7.8 | 2026-09-07 | Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7. | |
| CVE-2026-86310 | MEDIUM | 6.3 | 2026-09-07 | A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/cust_edit1.php. Such manipulat… | |
| CVE-2026-86309 | MEDIUM | 6.3 | 2026-09-07 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_searchfrm.php. This manipulation of the argumen… | |
| CVE-2026-86308 | MEDIUM | 5.3 | 2026-09-07 | A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unknown processing … | |
| CVE-2026-86307 | MEDIUM | 4.3 | 2026-09-07 | A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This vulnerability affects un… |