Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

790 CVEs · Medium severity

CVEs (790, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 790 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9745 MEDIUM 6.5 2026-09-03 IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This om…
CVE-2026-9744 MEDIUM 5.3 2026-09-03 IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitiv…
CVE-2026-9736 MEDIUM 5.3 2026-09-03 IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements w…
CVE-2026-9186 MEDIUM 6.5 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 h…
CVE-2026-9138 MEDIUM 6.5 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFi…
CVE-2026-9036 MEDIUM 5.9 2026-09-03 IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitiv…
CVE-2026-86597 MEDIUM 6.5 2026-09-08 Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encrypti…
CVE-2026-86550 MEDIUM 6.5 2026-09-08 NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This resul…
CVE-2026-86519 MEDIUM 5.3 2026-09-08 A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handle…
CVE-2026-86518 MEDIUM 6.3 2026-09-08 A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument ID lead…
CVE-2026-86517 MEDIUM 6.3 2026-09-08 A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a man…
CVE-2026-86516 MEDIUM 4.7 2026-09-08 A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-…
CVE-2026-86515 MEDIUM 4.3 2026-09-08 A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such manip…
CVE-2026-86514 MEDIUM 6.3 2026-09-08 A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation ca…
CVE-2026-86513 MEDIUM 5.3 2026-09-08 A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/…
CVE-2026-86512 MEDIUM 6.3 2026-09-08 A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/git…
CVE-2026-86511 MEDIUM 5.3 2026-09-08 A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal.toPlainString of the file src/main/java/com/gi…
CVE-2026-86506 MEDIUM Patched 5.9 2026-09-07 In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data
CVE-2026-86500 MEDIUM Patched 5.5 2026-09-07 In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin
CVE-2026-86499 MEDIUM Patched 4.3 2026-09-07 In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission
CVE-2026-86497 MEDIUM Patched 6.8 2026-09-07 In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials
CVE-2026-86496 MEDIUM Patched 4.3 2026-09-07 In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses
CVE-2026-86495 MEDIUM Patched 6.5 2026-09-07 In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects
CVE-2026-86493 MEDIUM Patched 6.5 2026-09-07 In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards
CVE-2026-86490 MEDIUM Patched 6.5 2026-09-07 In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint