Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

EOL hidden · Show all products

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2020-37277 MEDIUM Patched 6.5 2026-09-06 PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send s…
CVE-2021-38489 HIGH 8.2 2026-09-03 HDD password plaintext is stored in a UEFI variable.
CVE-2021-43613 MEDIUM 6.5 2026-09-03 An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User and administrator password hashes are exposed in runtime UEFI variables, leading to escalation of privilege
CVE-2021-43614 MEDIUM 6.7 2026-09-03 Error in handling the PlatformLangCodes UEFI variable could cause a buffer overflow, leading to resource exhaustion and failure.
CVE-2021-44319 HIGH 7.5 2026-09-04 Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication attack, allowing remote and unaut…
CVE-2021-44320 HIGH 7.5 2026-09-04 Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., video s…
CVE-2021-48006 LOW Patched 3.3 2026-09-06 PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but on…
CVE-2021-48007 MEDIUM Patched 6.5 2026-09-06 PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packet…
CVE-2022-26961 NONE — 2026-09-04 Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the na…
CVE-2022-35497 NONE — 2026-09-04 In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid session cookies via reflected cross-site scripting aff…
CVE-2022-35499 HIGH 7.1 2026-09-04 In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.
CVE-2022-51008 MEDIUM Patched 5.3 2026-09-06 PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without sending LoginPacket. Attackers …
CVE-2022-51009 HIGH Patched 7.5 2026-09-06 PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin pack…
CVE-2022-51010 MEDIUM Patched 6.5 2026-09-07 PocketMine-MP versions before 4.4.2 fail to properly validate item IDs received from clients in itemstack NBT data. Attackers can send crafted item IDs outside the valid ra…
CVE-2022-51011 MEDIUM Patched 4.3 2026-09-07 PocketMine-MP before 4.2.10 fails to validate the total length of incoming chat message blobs before splitting them by newline characters, allowing attackers to send large …
CVE-2022-51012 MEDIUM Patched 6.5 2026-09-07 PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafte…
CVE-2022-51013 MEDIUM Patched 6.5 2026-09-07 PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data received from clients. Attackers can send negative or out-of-ran…
CVE-2022-51014 MEDIUM Patched 6.5 2026-09-07 PocketMine-MP before 4.0.7 contains an unhandled exception vulnerability in the ModalFormResponsePacket handler when processing malformed JSON from clients. Attackers can s…
CVE-2022-51015 MEDIUM Patched 6.5 2026-09-07 PocketMine-MP before 4.0.6 does not validate facing values in PlayerActionPacket (for START_BREAK and CRACK_BREAK actions) or in UseItemTransactionData (typically within In…
CVE-2022-51016 MEDIUM Patched 6.1 2026-09-07 PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft Bedrock protocol encryption, so the server cannot verify that a connecting client possesses the private key c…
CVE-2022-51017 HIGH Patched 7.5 2026-09-07 PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 byte TAG_S…
CVE-2022-51018 MEDIUM Patched 6.5 2026-09-07 PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not limit book page text length, page count, or author/title length. A player who obtains a writable book can create…
CVE-2023-20576 HIGH 7.7 2026-09-02 Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation.
CVE-2023-20577 HIGH 7.4 2026-09-02 A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution.
CVE-2023-3360 LOW Patched 3.3 2026-09-02 The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege use…