Search
8,720 CVEs · Medium severity
CVEs (8,720, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 8,720 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-31677 | MEDIUM | Patched | 5.5 | 2026-04-25 | In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - limit RX SG extraction by receive buffer budget Make af_alg_get_rsgl() limit each RX … |
| CVE-2026-31681 | MEDIUM | Patched | 5.5 | 2026-04-25 | In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_multiport: validate range encoding in checkentry ports_match_v1() treats any non-zero pf… |
| CVE-2026-31684 | MEDIUM | Patched | 5.5 | 2026-04-25 | In the Linux kernel, the following vulnerability has been resolved: net: sched: act_csum: validate nested VLAN headers tcf_csum_act() walks nested VLAN headers directly f… |
| CVE-2026-6978 | MEDIUM | 4.7 | 2026-04-25 | A vulnerability was detected in JiZhiCMS up to 2.5.6. The impacted element is the function htmlspecialchars_decode of the file /index.php/admins/Sys/addcache.html. The mani… | |
| CVE-2026-6979 | MEDIUM | 6.3 | 2026-04-25 | A flaw has been found in devlikeapro WAHA up to 2026.3.4. This affects an unknown function of the file src/api/media.controller.ts of the component API Request Handler. Thi… | |
| CVE-2026-6981 | MEDIUM | 6.3 | 2026-04-25 | A vulnerability was found in IhateCreatingUserNames2 AiraHub2 up to 3e4b77fd7d48ed811ffe5b8d222068c17c76495e. Affected is the function connect_stream_endpoint/sync_agents o… | |
| CVE-2026-6982 | MEDIUM | 6.3 | 2026-04-25 | A vulnerability was determined in star7th ShowDoc up to 2.10.10/3.6.2/3.8.0. Affected by this vulnerability is an unknown functionality of the file server/Application/Api/C… | |
| CVE-2026-6983 | MEDIUM | 4.7 | 2026-04-25 | A vulnerability was identified in pagekit up to 1.0.18. Affected by this issue is some unknown functionality of the file /index.php/admin/system/update/download. The manipu… | |
| CVE-2026-6984 | MEDIUM | 4.7 | 2026-04-25 | A security flaw has been discovered in AstrBotDevs AstrBot up to 4.22.1. This affects the function create_template of the file astrbot/dashboard/routes/t2i.py of the compon… | |
| CVE-2026-6985 | MEDIUM | Patched | 5.3 | 2026-04-25 | A weakness has been identified in Cesanta Mongoose up to 7.20. This vulnerability affects the function handle_opt of the file /src/net_builtin.c of the component TCP Option… |
| CVE-2026-6989 | MEDIUM | 6.3 | 2026-04-25 | A vulnerability has been found in Tenda F453 up to 1.0.0.3. Impacted is the function TendaTelnet of the file /goform/telnet of the component Telnet Service. Such manipulati… | |
| CVE-2026-6991 | MEDIUM | 6.3 | 2026-04-25 | A vulnerability was determined in colinhacks Zod up to 4.3.6. The impacted element is an unknown function of the file packages/zod/src/v4/core/regexes.ts of the component C… | |
| CVE-2026-6993 | MEDIUM | 5.3 | 2026-04-25 | A security flaw has been discovered in go-kratos kratos up to 2.9.2. This impacts the function NewServer of the file transport/http/server.go of the component http.DefaultS… | |
| CVE-2026-6994 | MEDIUM | 6.3 | 2026-04-25 | A weakness has been identified in Envoy up to 1.33.0. Affected is the function params.add of the file source/extensions/filters/http/header_mutation/header_mutation.cc of t… | |
| CVE-2026-42254 | MEDIUM | 4.0 | 2026-04-26 | Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associated with a query that triggered a response. | |
| CVE-2026-7018 | MEDIUM | 5.6 | 2026-04-26 | A vulnerability was determined in Datavane Datavines up to 13607645e14a4982468cfdbcf75c85cde63bae71. The affected element is an unknown function of the file datavines-core/… | |
| CVE-2026-7023 | MEDIUM | Patched | 6.3 | 2026-04-26 | A vulnerability was detected in ByteDance coze-studio up to 0.5.1. Affected by this vulnerability is the function ExecuteSQL of the file backend/domain/memory/database/serv… |
| CVE-2026-7024 | MEDIUM | 5.4 | 2026-04-26 | A flaw has been found in rawchen sims up to 004f783b1db5ecdfad81c8fdc3b34171211112de. Affected by this issue is some unknown functionality of the file sims-master/src/web/s… | |
| CVE-2026-7026 | MEDIUM | 4.5 | 2026-04-26 | A vulnerability was determined in D-Link DGS-3420 1.50.018. This issue affects some unknown processing of the component System Information Settings Page. This manipulation … | |
| CVE-2026-7028 | MEDIUM | 4.7 | 2026-04-26 | A security flaw has been discovered in CodeAstro Online Job Portal 1.0. The affected element is an unknown function of the file /admin/jobs-admins/delete-jobs.php of the co… | |
| CVE-2018-25264 | MEDIUM | 6.2 | 2026-04-26 | TransMac 12.2 contains a buffer overflow vulnerability in the license key input field that allows local attackers to crash the application by submitting an oversized string… | |
| CVE-2018-25273 | MEDIUM | 6.2 | 2026-04-26 | CrossFont 7.5 contains a buffer overflow vulnerability that allows local attackers to crash the application by submitting an oversized payload in the License Key field. Att… | |
| CVE-2018-25274 | MEDIUM | 6.2 | 2026-04-26 | InfraRecorder 0.53 contains a denial of service vulnerability that allows local attackers to crash the application by importing a maliciously crafted text file. Attackers c… | |
| CVE-2018-25275 | MEDIUM | 6.2 | 2026-04-26 | Faleemi Plus 1.0.2 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying oversized input strings. Attackers can paste a… | |
| CVE-2018-25276 | MEDIUM | 5.5 | 2026-04-26 | RoboImport 1.2.0.72 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input to registration fields. At… |