Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

13,088 CVEs

CVEs (13,088, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 126–150 of 13,088 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-86425 LOW Patched 3.3 2026-09-07 ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted li…
CVE-2026-86424 LOW Patched 2.5 2026-09-07 ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write…
CVE-2026-86423 LOW Patched 3.3 2026-09-07 ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick. A crafted call to the GetList metho…
CVE-2026-86422 LOW Patched 3.3 2026-09-07 ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restricti…
CVE-2026-86421 LOW Patched 3.7 2026-09-07 ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allow…
CVE-2026-86420 LOW Patched 3.7 2026-09-07 ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can …
CVE-2026-86419 NONE — 2026-09-07 Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processin…
CVE-2026-86418 NONE — 2026-09-07 Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal or…
CVE-2026-86417 NONE — 2026-09-07 Affected versions of MISP inconsistently enforced email-address visibility in DashboardsController::listTemplates(). The query always fetched User.email, while redaction …
CVE-2026-86416 MEDIUM Patched 5.4 2026-09-07 ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform…
CVE-2026-86408 NONE — 2026-09-07 Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queri…
CVE-2026-86404 HIGH 8.8 2026-09-07 EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list…
CVE-2026-86351 NONE — 2026-09-07 Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /. That check is insufficient because protocol-rela…
CVE-2026-86347 NONE — 2026-09-07 Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This …
CVE-2026-86342 NONE — 2026-09-07 Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes fro…
CVE-2026-86332 MEDIUM 6.5 2026-09-07 A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard ser…
CVE-2026-86321 MEDIUM 5.3 2026-09-07 A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jacks…
CVE-2026-86319 MEDIUM 5.3 2026-09-07 A vulnerability has been found in java-json-tools json-patch up to 1.13. Affected by this vulnerability is the function JsonPatch.apply of the file src/main/java/com/github…
CVE-2026-86318 MEDIUM 5.3 2026-09-07 A flaw has been found in java-json-tools json-patch up to 1.13. Affected is the function JsonMergePatch.fromJson of the file JsonMergePatchDeserializer.java. Executing a ma…
CVE-2026-86317 MEDIUM 5.3 2026-09-07 A vulnerability was detected in ggml-org llama.cpp up to 0.4.0. This impacts the function rpc_server::deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the c…
CVE-2026-86315 MEDIUM 6.2 2026-09-07 An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt nati…
CVE-2026-86314 MEDIUM 6.2 2026-09-07 Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds…
CVE-2026-86313 HIGH 7.8 2026-09-07 Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.
CVE-2026-86310 MEDIUM 6.3 2026-09-07 A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/cust_edit1.php. Such manipulat…
CVE-2026-86309 MEDIUM 6.3 2026-09-07 A flaw has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_searchfrm.php. This manipulation of the argumen…