Search
13,088 CVEs
CVEs (13,088, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 126–150 of 13,088 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86193 | NONE | Patched | — | 2026-09-05 | grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts… |
| CVE-2026-86194 | NONE | Patched | — | 2026-09-05 | Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined on … |
| CVE-2026-86195 | NONE | Patched | — | 2026-09-05 | grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested supe… |
| CVE-2026-86196 | NONE | Patched | — | 2026-09-05 | Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redi… |
| CVE-2026-52777 | NONE | Patched | — | 2026-09-05 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This iss… |
| CVE-2026-52762 | NONE | Patched | — | 2026-09-05 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) vulnerability in the semantic templat… |
| CVE-2026-46636 | NONE | Patched | — | 2026-09-04 | Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instan… |
| CVE-2026-50894 | NONE | — | 2026-09-04 | easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to ex… | |
| CVE-2026-75439 | NONE | — | 2026-09-04 | An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component | |
| CVE-2026-79426 | NONE | — | 2026-09-04 | An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafte… | |
| CVE-2022-26961 | NONE | — | 2026-09-04 | Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the na… | |
| CVE-2026-79389 | NONE | — | 2026-09-04 | Trueview T18161 S 6.0.23.4 contains an improper verification in MQTT command processing. An attacker with network access can replay or modify captured MQTT messages, includ… | |
| CVE-2026-79390 | NONE | — | 2026-09-04 | Trueview TI8161 6.0.23.4 is vulnerable to information disclosure due to the transmission of MQTT communications in plaintext over TCP port 1883. An unauthenticated attacker… | |
| CVE-2026-71622 | NONE | — | 2026-09-04 | SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote attacker to obtain sensitive information via the User.php component | |
| CVE-2026-71625 | NONE | — | 2026-09-04 | An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component | |
| CVE-2026-53602 | NONE | Patched | — | 2026-09-04 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host that should no longer be trusted obt… |
| CVE-2026-53603 | NONE | Patched | — | 2026-09-04 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table… |
| CVE-2026-53604 | NONE | Patched | — | 2026-09-04 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, the web handler renderMobileBundle passes the real *pki.CAResolver directly in… |
| CVE-2026-78839 | NONE | — | 2026-09-04 | An arbitrary file upload vulnerability in AppNitro MachForm v30 allows attackers to execute arbitrary code via uploading a crafted .phar file. | |
| CVE-2026-71620 | NONE | — | 2026-09-04 | File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remote attacker to execute arbitrary code via a crafted .php file | |
| CVE-2026-80912 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: selinux: reject an unclaimed class value in security_get_classes() security_get_classes() sizes an arr… | |
| CVE-2026-80913 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: selinux: require every boolean value to be defined p_bools.nprim comes from the policy image independe… | |
| CVE-2026-80905 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: net: tap: fix wrong transport_header when sending VLAN-tagged frame In tap_get_user_xdp(), when proces… | |
| CVE-2026-80906 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: net: packet: fix wrong transport_header when sending VLAN-tagged frame In packet_parse_headers(), when… | |
| CVE-2026-80907 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix UVD dpb min size calculation for H264 This should use actual number of references from… |