Search
2,281 CVEs
CVEs (2,281, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 101–125 of 2,281 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-79389 | NONE | — | 2026-09-04 | Trueview T18161 S 6.0.23.4 contains an improper verification in MQTT command processing. An attacker with network access can replay or modify captured MQTT messages, includ… | |
| CVE-2026-79390 | NONE | — | 2026-09-04 | Trueview TI8161 6.0.23.4 is vulnerable to information disclosure due to the transmission of MQTT communications in plaintext over TCP port 1883. An unauthenticated attacker… | |
| CVE-2026-79391 | NONE | — | 2026-09-04 | No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP port 1883 without requiring authentication, allowing a … | |
| CVE-2026-71622 | NONE | — | 2026-09-04 | SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote attacker to obtain sensitive information via the User.php component | |
| CVE-2026-71624 | NONE | — | 2026-09-04 | An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php,… | |
| CVE-2026-71625 | NONE | — | 2026-09-04 | An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component | |
| CVE-2026-71626 | NONE | — | 2026-09-04 | An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php… | |
| CVE-2026-53602 | NONE | Patched | — | 2026-09-04 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host that should no longer be trusted obt… |
| CVE-2026-53603 | NONE | Patched | — | 2026-09-04 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table… |
| CVE-2026-53604 | NONE | Patched | — | 2026-09-04 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, the web handler renderMobileBundle passes the real *pki.CAResolver directly in… |
| CVE-2026-78839 | NONE | — | 2026-09-04 | An arbitrary file upload vulnerability in AppNitro MachForm v30 allows attackers to execute arbitrary code via uploading a crafted .phar file. | |
| CVE-2026-71620 | NONE | — | 2026-09-04 | File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remote attacker to execute arbitrary code via a crafted .php file | |
| CVE-2026-80912 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: selinux: reject an unclaimed class value in security_get_classes() security_get_classes() sizes an arr… | |
| CVE-2026-80913 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: selinux: require every boolean value to be defined p_bools.nprim comes from the policy image independe… | |
| CVE-2026-80905 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: net: tap: fix wrong transport_header when sending VLAN-tagged frame In tap_get_user_xdp(), when proces… | |
| CVE-2026-80906 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: net: packet: fix wrong transport_header when sending VLAN-tagged frame In packet_parse_headers(), when… | |
| CVE-2026-80907 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix UVD dpb min size calculation for H264 This should use actual number of references from… | |
| CVE-2026-80908 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Reject UVD message with dimensions above 4096 Fixes potential overflow in DPB size calcula… | |
| CVE-2026-80909 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Reject UVD message with invalid number of h265 refs Same change as for h264, avoids overfl… | |
| CVE-2026-80910 | NONE | Patched | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses EAR SPKR PA Gain" and the four "WSA RX* Mux"… |
| CVE-2026-80911 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() If either tplg_ops->dai_config or … | |
| CVE-2026-80902 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA When terminating DMA transfers, ac… | |
| CVE-2026-80903 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Fix sync entry leak on OA config emit failure xe_oa_emit_oa_config() releases the sync entr… | |
| CVE-2026-80904 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: net/tls: Fail tls_sw_splice_read() after a failed async decrypt When an async decrypt fails, tls_decry… | |
| CVE-2026-80898 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: netfs: clear PG_private_2 on copy-to-cache append failure netfs_pgpriv2_copy_to_cache() marks the foli… |