Search
78,575 CVEs
CVEs (78,575, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 101–125 of 78,575 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-80229 | NONE | — | 2026-09-06 | When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl at… | |
| CVE-2026-80230 | NONE | — | 2026-09-06 | When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libc… | |
| CVE-2026-80231 | NONE | — | 2026-09-06 | A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`… | |
| CVE-2026-80255 | NONE | — | 2026-09-06 | A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie w… | |
| CVE-2026-82208 | NONE | — | 2026-09-06 | With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store af… | |
| CVE-2026-82209 | NONE | — | 2026-09-06 | When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly… | |
| CVE-2026-18924 | NONE | — | 2026-09-06 | A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup… | |
| CVE-2026-19931 | NONE | — | 2026-09-06 | A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credenti… | |
| CVE-2026-13608 | NONE | — | 2026-09-06 | A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An a… | |
| CVE-2026-82751 | NONE | Patched | — | 2026-09-06 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a lar… |
| CVE-2026-82750 | NONE | Patched | — | 2026-09-06 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a lar… |
| CVE-2026-86283 | NONE | — | 2026-09-06 | MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access … | |
| CVE-2026-86218 | NONE | Patched | — | 2026-09-06 | N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. |
| CVE-2026-76160 | NONE | — | 2026-09-05 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-76161 | NONE | — | 2026-09-05 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-67277 | NONE | Patched | — | 2026-09-05 | RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start a… |
| CVE-2026-67278 | NONE | Patched | — | 2026-09-05 | MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirect… |
| CVE-2026-67279 | NONE | Patched | — | 2026-09-05 | RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a… |
| CVE-2026-67281 | NONE | Patched | — | 2026-09-05 | RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer use… |
| CVE-2026-86060 | NONE | Patched | — | 2026-09-05 | RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask … |
| CVE-2026-86206 | NONE | Patched | — | 2026-09-05 | A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4 |
| CVE-2026-67276 | NONE | Patched | — | 2026-09-05 | RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting … |
| CVE-2026-86207 | NONE | — | 2026-09-05 | An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs | |
| CVE-2026-82752 | NONE | Patched | — | 2026-09-05 | Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of arbitrary size in an attribute whose length const… |
| CVE-2026-86197 | NONE | Patched | — | 2026-09-05 | Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper ou… |