Search
2,281 CVEs
CVEs (2,281, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 2,281 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86287 | NONE | Patched | — | 2026-09-07 | Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths. Non-numeric and non-ASCII prefix lengths are accepted and treated as 0. Integers over 31 bits a… |
| CVE-2026-16028 | NONE | Patched | — | 2026-09-07 | Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table. When a stream re… |
| CVE-2026-78254 | NONE | Patched | — | 2026-09-07 | The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated t… |
| CVE-2026-20512 | NONE | — | 2026-09-07 | In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has alread… | |
| CVE-2026-86304 | NONE | Patched | — | 2026-09-06 | MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor. pars… |
| CVE-2026-86219 | NONE | Patched | — | 2026-09-06 | Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_start generates a fresh… |
| CVE-2026-80229 | NONE | — | 2026-09-06 | When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl at… | |
| CVE-2026-80230 | NONE | — | 2026-09-06 | When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libc… | |
| CVE-2026-80231 | NONE | — | 2026-09-06 | A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`… | |
| CVE-2026-80255 | NONE | — | 2026-09-06 | A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie w… | |
| CVE-2026-82208 | NONE | — | 2026-09-06 | With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store af… | |
| CVE-2026-82209 | NONE | — | 2026-09-06 | When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly… | |
| CVE-2026-18924 | NONE | — | 2026-09-06 | A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup… | |
| CVE-2026-19931 | NONE | — | 2026-09-06 | A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credenti… | |
| CVE-2026-13608 | NONE | — | 2026-09-06 | A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An a… | |
| CVE-2026-76160 | NONE | — | 2026-09-05 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-76161 | NONE | — | 2026-09-05 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-50894 | NONE | — | 2026-09-04 | easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to ex… | |
| CVE-2026-75438 | NONE | — | 2026-09-04 | Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function | |
| CVE-2026-75439 | NONE | — | 2026-09-04 | An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component | |
| CVE-2026-79423 | NONE | — | 2026-09-04 | An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request. | |
| CVE-2026-79426 | NONE | — | 2026-09-04 | An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafte… | |
| CVE-2025-67066 | NONE | — | 2026-09-04 | SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path | |
| CVE-2022-26961 | NONE | — | 2026-09-04 | Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the na… | |
| CVE-2026-79389 | NONE | — | 2026-09-04 | Trueview T18161 S 6.0.23.4 contains an improper verification in MQTT command processing. An attacker with network access can replay or modify captured MQTT messages, includ… |