Search
2,281 CVEs
CVEs (2,281, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 2,281 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-37277 | MEDIUM | Patched | 6.5 | 2026-09-06 | PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send s… |
| CVE-2021-38489 | HIGH | 8.2 | 2026-09-03 | HDD password plaintext is stored in a UEFI variable. | |
| CVE-2021-43613 | MEDIUM | 6.5 | 2026-09-03 | An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User and administrator password hashes are exposed in runtime UEFI variables, leading to escalation of privilege | |
| CVE-2021-43614 | MEDIUM | 6.7 | 2026-09-03 | Error in handling the PlatformLangCodes UEFI variable could cause a buffer overflow, leading to resource exhaustion and failure. | |
| CVE-2021-44319 | NONE | — | 2026-09-04 | Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication attack, allowing remote and unaut… | |
| CVE-2021-44320 | HIGH | 7.5 | 2026-09-04 | Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., video s… | |
| CVE-2021-48006 | LOW | Patched | 3.3 | 2026-09-06 | PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but on… |
| CVE-2021-48007 | MEDIUM | Patched | 6.5 | 2026-09-06 | PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packet… |
| CVE-2022-26961 | NONE | — | 2026-09-04 | Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the na… | |
| CVE-2022-35497 | NONE | — | 2026-09-04 | In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid session cookies via reflected cross-site scripting aff… | |
| CVE-2022-35499 | HIGH | 7.1 | 2026-09-04 | In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL. | |
| CVE-2022-51008 | MEDIUM | Patched | 5.3 | 2026-09-06 | PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without sending LoginPacket. Attackers … |
| CVE-2022-51009 | HIGH | Patched | 7.5 | 2026-09-06 | PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin pack… |
| CVE-2022-51010 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP versions before 4.4.2 fail to properly validate item IDs received from clients in itemstack NBT data. Attackers can send crafted item IDs outside the valid ra… |
| CVE-2022-51011 | MEDIUM | Patched | 4.3 | 2026-09-07 | PocketMine-MP before 4.2.10 fails to validate the total length of incoming chat message blobs before splitting them by newline characters, allowing attackers to send large … |
| CVE-2022-51012 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafte… |
| CVE-2022-51013 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data received from clients. Attackers can send negative or out-of-ran… |
| CVE-2022-51014 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP before 4.0.7 contains an unhandled exception vulnerability in the ModalFormResponsePacket handler when processing malformed JSON from clients. Attackers can s… |
| CVE-2022-51015 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP before 4.0.6 does not validate facing values in PlayerActionPacket (for START_BREAK and CRACK_BREAK actions) or in UseItemTransactionData (typically within In… |
| CVE-2022-51016 | MEDIUM | Patched | 6.1 | 2026-09-07 | PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft Bedrock protocol encryption, so the server cannot verify that a connecting client possesses the private key c… |
| CVE-2022-51017 | HIGH | Patched | 7.5 | 2026-09-07 | PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 byte TAG_S… |
| CVE-2022-51018 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not limit book page text length, page count, or author/title length. A player who obtains a writable book can create… |
| CVE-2023-20576 | HIGH | 7.7 | 2026-09-02 | Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation. | |
| CVE-2023-20577 | HIGH | 7.4 | 2026-09-02 | A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution. | |
| CVE-2023-3360 | LOW | Patched | 3.3 | 2026-09-02 | The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege use… |