Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 126–150 of 30,217 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-71375 | HIGH | Patched | 7.4 | 2026-09-08 | Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 bef… |
| CVE-2026-71374 | CRITICAL | Patched | 9.8 | 2026-09-08 | Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 1… |
| CVE-2026-48888 | HIGH | Patched | 7.5 | 2026-09-08 | Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0. |
| CVE-2026-86519 | MEDIUM | 5.3 | 2026-09-08 | A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handle… | |
| CVE-2026-86518 | MEDIUM | 6.3 | 2026-09-08 | A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument ID lead… | |
| CVE-2026-86517 | MEDIUM | 6.3 | 2026-09-08 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a man… | |
| CVE-2026-86516 | MEDIUM | 4.7 | 2026-09-08 | A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-… | |
| CVE-2026-86515 | MEDIUM | 4.3 | 2026-09-08 | A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such manip… | |
| CVE-2026-86514 | MEDIUM | 6.3 | 2026-09-08 | A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation ca… | |
| CVE-2026-86513 | MEDIUM | 5.3 | 2026-09-08 | A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/… | |
| CVE-2026-86512 | MEDIUM | 6.3 | 2026-09-08 | A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/git… | |
| CVE-2026-86511 | MEDIUM | 5.3 | 2026-09-08 | A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal.toPlainString of the file src/main/java/com/gi… | |
| CVE-2026-75811 | NONE | — | 2026-09-08 | Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause h… | |
| CVE-2026-75810 | NONE | — | 2026-09-08 | Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigg… | |
| CVE-2026-75809 | NONE | — | 2026-09-08 | Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver au… | |
| CVE-2026-75808 | NONE | — | 2026-09-08 | Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by by… | |
| CVE-2026-19397 | NONE | — | 2026-09-08 | Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the… | |
| CVE-2026-18023 | NONE | — | 2026-09-08 | Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via … | |
| CVE-2026-16006 | NONE | — | 2026-09-08 | Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCT… | |
| CVE-2026-16005 | NONE | — | 2026-09-08 | Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verificat… | |
| CVE-2026-16004 | NONE | — | 2026-09-08 | Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL reques… | |
| CVE-2026-16003 | NONE | — | 2026-09-08 | Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IO… | |
| CVE-2026-12962 | NONE | — | 2026-09-08 | A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a … | |
| CVE-2026-86510 | CRITICAL | 9.9 | 2026-09-08 | A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to… | |
| CVE-2026-86509 | CRITICAL | 9.6 | 2026-09-08 | A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulati… |