Search
565 CVEs · published 2026-09-24 to 2026-09-24
CVEs (565, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 565 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32000 | MEDIUM | 4.3 | 2026-09-24 | HCL Sametime is vulnerable to insufficient input sanitization. The application did not appropriately sanitize user input. When user input is implicitly or explicitly truste… | |
| CVE-2026-11744 | NONE | — | 2026-09-24 | An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fails to properly sanitize input received during the N… | |
| CVE-2026-12227 | CRITICAL | 9.8 | 2026-09-24 | The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` paramete… | |
| CVE-2026-12559 | NONE | — | 2026-09-24 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain … | |
| CVE-2026-13016 | NONE | Patched | — | 2026-09-24 | ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certa… |
| CVE-2026-13248 | HIGH | 8.8 | 2026-09-24 | An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD4… | |
| CVE-2026-13249 | CRITICAL | 9.8 | 2026-09-24 | An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040,… | |
| CVE-2026-13465 | HIGH | 8.1 | 2026-09-24 | Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affe… | |
| CVE-2026-13466 | HIGH | 8.1 | 2026-09-24 | Incorrect calculation of buffer size vulnerability in Altera Trusted Firmware on HPS allows Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0. | |
| CVE-2026-13467 | HIGH | 8.1 | 2026-09-24 | Out-of-bounds write vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trus… | |
| CVE-2026-14441 | NONE | — | 2026-09-24 | A logic flaw in Java cache key handling object comparison handling could lead to improper identifier resolution when processing specific user account structures. The issue … | |
| CVE-2026-14442 | NONE | — | 2026-09-24 | An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be written to application logs in plain text. When scheduled… | |
| CVE-2026-14443 | NONE | Patched | — | 2026-09-24 | Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system log… |
| CVE-2026-14780 | NONE | — | 2026-09-24 | A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and access restrictions within the embedded executio… | |
| CVE-2026-15731 | MEDIUM | 6.4 | 2026-09-24 | The WP Multilang – Translation and Multilingual Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post content in all versions up to, and inc… | |
| CVE-2026-16302 | MEDIUM | 4.3 | 2026-09-24 | The Spectra Legacy – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0 via the editor_asset… | |
| CVE-2026-17413 | MEDIUM | 5.1 | 2026-09-24 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability i… | |
| CVE-2026-17503 | MEDIUM | 5.1 | 2026-09-24 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability i… | |
| CVE-2026-17504 | MEDIUM | 5.1 | 2026-09-24 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability i… | |
| CVE-2026-17511 | LOW | 3.4 | 2026-09-24 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability i… | |
| CVE-2026-18104 | LOW | 3.3 | 2026-09-24 | IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption. | |
| CVE-2026-18335 | MEDIUM | 5.4 | 2026-09-24 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including… | |
| CVE-2026-18467 | CRITICAL | 9.8 | 2026-09-24 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.3. The 5.0.3 patch introd… | |
| CVE-2026-18857 | LOW | 3.4 | 2026-09-24 | IBM OPENBMC FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in the BMC firmware management interfac… | |
| CVE-2026-18870 | MEDIUM | 4.3 | 2026-09-24 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 could allow a remote attacker to… |