Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 176–200 of 2,372 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-17622 | MEDIUM | 6.5 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted d… | |
| CVE-2026-17627 | MEDIUM | 4.9 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper … | |
| CVE-2026-17631 | MEDIUM | 5.0 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability. | |
| CVE-2026-18021 | MEDIUM | 6.5 | 2026-09-08 | The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including… | |
| CVE-2026-18023 | NONE | — | 2026-09-08 | Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via … | |
| CVE-2026-18056 | HIGH | 7.5 | 2026-09-06 | The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is… | |
| CVE-2026-18058 | HIGH | 7.5 | 2026-09-02 | The mobile Smart Connect dashboard UI was subject to manipulation by 3rd party apps. When paired with a phishing attack, this manipulation could result in escalated privile… | |
| CVE-2026-18073 | MEDIUM | 4.4 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements. | |
| CVE-2026-18076 | MEDIUM | 4.3 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak. | |
| CVE-2026-18078 | MEDIUM | 4.3 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow. | |
| CVE-2026-18149 | MEDIUM | Patched | 5.9 | 2026-09-04 | undici's retry handler can leave an already-exposed response body pending forever. When a server returns a successful response that declares a Content-Length, sends only pa… |
| CVE-2026-18167 | NONE | — | 2026-09-03 | A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit crafted input that… | |
| CVE-2026-18175 | HIGH | 8.1 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher. | |
| CVE-2026-18198 | HIGH | 8.8 | 2026-09-04 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN O… | |
| CVE-2026-18210 | CRITICAL | Patched | 9.8 | 2026-09-01 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and T… |
| CVE-2026-18221 | HIGH | 8.1 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters. | |
| CVE-2026-18238 | MEDIUM | 5.0 | 2026-09-05 | The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message a… | |
| CVE-2026-18313 | MEDIUM | 4.3 | 2026-09-05 | rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it l… | |
| CVE-2026-18329 | HIGH | 8.2 | 2026-09-02 | Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception i… | |
| CVE-2026-18330 | NONE | — | 2026-09-03 | A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may use the known shared … | |
| CVE-2026-18341 | MEDIUM | 6.3 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow. | |
| CVE-2026-18355 | HIGH | 7.5 | 2026-09-07 | A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire i… | |
| CVE-2026-18404 | MEDIUM | 6.4 | 2026-09-05 | The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all… | |
| CVE-2026-18406 | HIGH | 7.2 | 2026-09-05 | The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field Entity-Encoded … | |
| CVE-2026-18453 | HIGH | 7.5 | 2026-09-07 | A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash … |