Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

29,735 CVEs · Medium severity

CVEs (29,735, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 29,735 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-86142 MEDIUM Patched 6.9 2026-09-05 In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.
CVE-2026-86143 MEDIUM Patched 6.9 2026-09-05 In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for inte…
CVE-2026-86138 MEDIUM Patched 6.9 2026-09-05 In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
CVE-2026-86139 MEDIUM Patched 6.9 2026-09-05 In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
CVE-2026-55529 MEDIUM Patched 6.9 2026-08-25 PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _validate_origin method accepts request_origin.startswith(allowed), so the attacker-…
CVE-2026-16938 MEDIUM Patched 6.9 2026-08-19 IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in access contr…
CVE-2026-8810 MEDIUM 6.9 2026-08-19 On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables.
CVE-2026-52873 MEDIUM Patched 6.9 2026-08-18 Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.6.0, the wyzie-open-redeem IPC handler in index…
CVE-2026-54570 MEDIUM Patched 6.9 2026-08-18 AngleSharp is a .NET library for parsing angle bracket based hyper-texts. Prior to 1.5.0, MathAnnotationXmlElement in AngleSharp/Mathml/Dom/Internal/MathAnnotationXmlElemen…
CVE-2026-71313 MEDIUM Patched 6.9 2026-08-05 rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local…
CVE-2026-70611 MEDIUM Patched 6.9 2026-08-05 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools rev…
CVE-2026-18085 MEDIUM 6.9 2026-07-28 An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.
CVE-2026-53667 MEDIUM Patched 6.9 2026-07-27 React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. Th…
CVE-2026-53668 MEDIUM Patched 6.9 2026-07-27 React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker co…
CVE-2026-51385 MEDIUM 6.9 2026-07-20 An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fetch, _build_opener, _fet…
CVE-2026-53935 MEDIUM Patched 6.9 2026-07-07 Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLoc…
CVE-2026-13083 MEDIUM Patched 6.9 2026-06-26 A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An attacker with cluster adm…
CVE-2026-47693 MEDIUM 6.9 2026-06-23 Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 are vulnerable to CSV Injection (Formula Injection) in its log expo…
CVE-2026-56411 MEDIUM Patched 6.9 2026-06-21 xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
CVE-2026-56408 MEDIUM Patched 6.9 2026-06-21 libexpat before 2.8.2 has an integer overflow in copyString.
CVE-2026-56410 MEDIUM Patched 6.9 2026-06-21 xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
CVE-2026-56404 MEDIUM Patched 6.9 2026-06-21 libexpat before 2.8.2 has an integer overflow in addBinding.
CVE-2026-56405 MEDIUM Patched 6.9 2026-06-21 libexpat before 2.8.2 has an integer overflow in getAttributeId.
CVE-2026-56406 MEDIUM Patched 6.9 2026-06-21 libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
CVE-2026-56407 MEDIUM Patched 6.9 2026-06-21 libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.