Search
13,088 CVEs
CVEs (13,088, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 201–225 of 13,088 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-80773 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: HID: huawei: fix missing hid_is_usb() check to_usb_interface() can only be used on a hid_device whose … | |
| CVE-2026-80760 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255 mgmt_hci_cmd_sync() checks that the message … | |
| CVE-2026-80761 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: zero the sockaddr before returning it in getname iso_sock_getname() fills a struct soc… | |
| CVE-2026-80762 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Fix accept list UAF during suspend hci_update_event_filter_sync() walks hdev->acc… | |
| CVE-2026-80763 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: validate LE Set CIG Parameters response The Command Complete dispatch validates … | |
| CVE-2026-80764 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: fix LE list UAF on reset hci_cc_reset() clears the LE accept and resolving lists… | |
| CVE-2026-80765 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: HID: hyperv: validate initial device info bounds The Hyper-V synthetic HID host supplies SYNTH_HID_INI… | |
| CVE-2026-80766 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: HID: uclogic: fix use-after-free of inrange_timer on remove uclogic_remove() cancels the pen in-range … | |
| CVE-2026-79419 | NONE | — | 2026-09-04 | A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validatio… | |
| CVE-2026-80758 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: futex: Avoid private hash use-after-free on final put futex_private_hash_put() drops the reference to … | |
| CVE-2026-80759 | NONE | — | 2026-09-04 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_aml: validate firmware segment lengths aml_download_firmware() reads two lengths from t… | |
| CVE-2026-75170 | NONE | — | 2026-09-04 | Cross-site scripting (XSS) vulnerability in the /loginController/doLogin endpoint of the HubCore platform (version 14.1.1) allows a remote unauthenticated attacker to injec… | |
| CVE-2026-75171 | NONE | — | 2026-09-04 | An issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID session cookie handling component. | |
| CVE-2026-75429 | NONE | — | 2026-09-04 | PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the Server-Worker transport layer | |
| CVE-2026-75162 | NONE | — | 2026-09-04 | An information disclosure vulnerability in the opcua-configuration method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows any remote authen… | |
| CVE-2026-75166 | NONE | — | 2026-09-04 | Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows the low-privileged service user to execute /usr/bin/tcpdump as root without a pa… | |
| CVE-2026-75167 | NONE | — | 2026-09-04 | A broken access control vulnerability in the ugw-usr-edit method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated use… | |
| CVE-2022-35497 | NONE | — | 2026-09-04 | In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid session cookies via reflected cross-site scripting aff… | |
| CVE-2026-52691 | NONE | — | 2026-09-04 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module. … | |
| CVE-2026-82309 | NONE | Patched | — | 2026-09-04 | Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the name… |
| CVE-2026-85229 | NONE | Patched | — | 2026-09-04 | ** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI. This … |
| CVE-2026-80181 | NONE | Patched | — | 2026-09-04 | Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to … |
| CVE-2026-80755 | NONE | — | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: selinux: reject a permission value exceeding the class permission count perm_read() bounds a permissio… | |
| CVE-2026-80756 | NONE | — | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: selinux: do not cancel a policy conversion that never started sel_write_load() calls selinux_policy_ca… | |
| CVE-2026-80757 | NONE | — | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: selinux: reject a class permission count below its inherited common security_get_permissions() maps an… |