Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 176–200 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-17622 MEDIUM 6.5 2026-09-04 IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted d…
CVE-2026-17627 MEDIUM 4.9 2026-09-04 IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper …
CVE-2026-17631 MEDIUM 5.0 2026-09-04 IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.
CVE-2026-18021 MEDIUM 6.5 2026-09-08 The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including…
CVE-2026-18023 NONE — 2026-09-08 Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via …
CVE-2026-18056 HIGH 7.5 2026-09-06 The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is…
CVE-2026-18058 HIGH 7.5 2026-09-02 The mobile Smart Connect dashboard UI was subject to manipulation by 3rd party apps. When paired with a phishing attack, this manipulation could result in escalated privile…
CVE-2026-18073 MEDIUM 4.4 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements.
CVE-2026-18076 MEDIUM 4.3 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak.
CVE-2026-18078 MEDIUM 4.3 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow.
CVE-2026-18149 MEDIUM Patched 5.9 2026-09-04 undici's retry handler can leave an already-exposed response body pending forever. When a server returns a successful response that declares a Content-Length, sends only pa…
CVE-2026-18167 NONE — 2026-09-03 A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit crafted input that…
CVE-2026-18175 HIGH 8.1 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.
CVE-2026-18198 HIGH 8.8 2026-09-04 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN O…
CVE-2026-18210 CRITICAL Patched 9.8 2026-09-01 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and T…
CVE-2026-18221 HIGH 8.1 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
CVE-2026-18238 MEDIUM 5.0 2026-09-05 The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message a…
CVE-2026-18313 MEDIUM 4.3 2026-09-05 rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it l…
CVE-2026-18329 HIGH 8.2 2026-09-02 Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception i…
CVE-2026-18330 NONE — 2026-09-03 A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may use the known shared …
CVE-2026-18341 MEDIUM 6.3 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.
CVE-2026-18355 HIGH 7.5 2026-09-07 A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire i…
CVE-2026-18404 MEDIUM 6.4 2026-09-05 The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all…
CVE-2026-18406 HIGH 7.2 2026-09-05 The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field Entity-Encoded …
CVE-2026-18453 HIGH 7.5 2026-09-07 A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash …