Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

12,997 CVEs

CVEs (12,997, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 12,997 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9859 MEDIUM Patched 6.5 2026-08-17 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which a&hellip;
CVE-2026-9854 NONE &mdash; 2026-09-03 A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying W&hellip;
CVE-2026-9853 NONE &mdash; 2026-09-03 A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects wi&hellip;
CVE-2026-9852 NONE &mdash; 2026-09-03 A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, dep&hellip;
CVE-2026-9816 HIGH Patched 8.3 2026-08-17 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which&hellip;
CVE-2026-9805 LOW 2.7 2026-08-26 SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size and could cause buffer overflow.
CVE-2026-9771 HIGH 8.8 2026-08-17 The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USERSPACE enabled, this handler is the kernel-side trus&hellip;
CVE-2026-9769 HIGH Patched 7.5 2026-08-23 justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() uncondit&hellip;
CVE-2026-9767 MEDIUM 6.5 2026-08-16 The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and in&hellip;
CVE-2026-9745 MEDIUM 6.5 2026-09-03 IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This om&hellip;
CVE-2026-9744 MEDIUM 5.3 2026-09-03 IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitiv&hellip;
CVE-2026-9736 MEDIUM 5.3 2026-09-03 IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements w&hellip;
CVE-2026-9728 MEDIUM 6.4 2026-08-24 The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out of live users&hellip;
CVE-2026-9693 LOW Patched 3.5 2026-08-17 Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a &hellip;
CVE-2026-9668 MEDIUM 6.3 2026-08-26 With legitimate user credentials in hand, attackers can construct malicious SQL statements to bypass authentication logic and execute arbitrary database queries directly. T&hellip;
CVE-2026-9637 NONE &mdash; 2026-09-01 A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length durin&hellip;
CVE-2026-9634 NONE &mdash; 2026-09-01 A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one or &hellip;
CVE-2026-9633 NONE &mdash; 2026-09-01 A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one or&hellip;
CVE-2026-9625 NONE &mdash; 2026-09-01 A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic service to c&hellip;
CVE-2026-9624 NONE &mdash; 2026-09-01 A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length valida&hellip;
CVE-2026-9622 NONE &mdash; 2026-09-01 A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic service to crash, r&hellip;
CVE-2026-9621 NONE &mdash; 2026-09-01 A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the &hellip;
CVE-2026-9548 MEDIUM Patched 6.5 2026-08-28 An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows re&hellip;
CVE-2026-9491 MEDIUM Patched 4.3 2026-08-28 A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive information.
CVE-2026-9331 HIGH 7.1 2026-09-08 The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing &hellip;