Search
29,735 CVEs · Medium severity
CVEs (29,735, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 29,735 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86142 | MEDIUM | Patched | 6.9 | 2026-09-05 | In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation. |
| CVE-2026-86143 | MEDIUM | Patched | 6.9 | 2026-09-05 | In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for inte… |
| CVE-2026-86138 | MEDIUM | Patched | 6.9 | 2026-09-05 | In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow. |
| CVE-2026-86139 | MEDIUM | Patched | 6.9 | 2026-09-05 | In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. |
| CVE-2026-55529 | MEDIUM | Patched | 6.9 | 2026-08-25 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _validate_origin method accepts request_origin.startswith(allowed), so the attacker-… |
| CVE-2026-16938 | MEDIUM | Patched | 6.9 | 2026-08-19 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in access contr… |
| CVE-2026-8810 | MEDIUM | 6.9 | 2026-08-19 | On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables. | |
| CVE-2026-52873 | MEDIUM | Patched | 6.9 | 2026-08-18 | Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.6.0, the wyzie-open-redeem IPC handler in index… |
| CVE-2026-54570 | MEDIUM | Patched | 6.9 | 2026-08-18 | AngleSharp is a .NET library for parsing angle bracket based hyper-texts. Prior to 1.5.0, MathAnnotationXmlElement in AngleSharp/Mathml/Dom/Internal/MathAnnotationXmlElemen… |
| CVE-2026-71313 | MEDIUM | Patched | 6.9 | 2026-08-05 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local… |
| CVE-2026-70611 | MEDIUM | Patched | 6.9 | 2026-08-05 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools rev… |
| CVE-2026-18085 | MEDIUM | 6.9 | 2026-07-28 | An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service. | |
| CVE-2026-53667 | MEDIUM | Patched | 6.9 | 2026-07-27 | React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. Th… |
| CVE-2026-53668 | MEDIUM | Patched | 6.9 | 2026-07-27 | React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker co… |
| CVE-2026-51385 | MEDIUM | 6.9 | 2026-07-20 | An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fetch, _build_opener, _fet… | |
| CVE-2026-53935 | MEDIUM | Patched | 6.9 | 2026-07-07 | Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLoc… |
| CVE-2026-13083 | MEDIUM | Patched | 6.9 | 2026-06-26 | A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An attacker with cluster adm… |
| CVE-2026-47693 | MEDIUM | 6.9 | 2026-06-23 | Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 are vulnerable to CSV Injection (Formula Injection) in its log expo… | |
| CVE-2026-56411 | MEDIUM | Patched | 6.9 | 2026-06-21 | xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations. |
| CVE-2026-56408 | MEDIUM | Patched | 6.9 | 2026-06-21 | libexpat before 2.8.2 has an integer overflow in copyString. |
| CVE-2026-56410 | MEDIUM | Patched | 6.9 | 2026-06-21 | xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. |
| CVE-2026-56404 | MEDIUM | Patched | 6.9 | 2026-06-21 | libexpat before 2.8.2 has an integer overflow in addBinding. |
| CVE-2026-56405 | MEDIUM | Patched | 6.9 | 2026-06-21 | libexpat before 2.8.2 has an integer overflow in getAttributeId. |
| CVE-2026-56406 | MEDIUM | Patched | 6.9 | 2026-06-21 | libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse. |
| CVE-2026-56407 | MEDIUM | Patched | 6.9 | 2026-06-21 | libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen. |