Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,107 CVEs

EOL hidden · Show all products

CVEs (30,107, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 30,107 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-77654 NONE — 2026-09-08 Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Inj…
CVE-2026-19614 NONE — 2026-09-08 The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3.
CVE-2026-85400 NONE — 2026-09-08 Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This al…
CVE-2026-86590 NONE Patched — 2026-09-08 In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP…
CVE-2026-77132 NONE — 2026-09-08 It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged …
CVE-2026-75811 NONE — 2026-09-08 Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause h…
CVE-2026-18023 NONE — 2026-09-08 Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via …
CVE-2026-19397 NONE — 2026-09-08 Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the…
CVE-2026-75808 NONE — 2026-09-08 Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by by…
CVE-2026-75809 NONE — 2026-09-08 Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver au…
CVE-2026-75810 NONE — 2026-09-08 Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigg…
CVE-2026-12962 NONE — 2026-09-08 A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a …
CVE-2026-16003 NONE — 2026-09-08 Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IO…
CVE-2026-16004 NONE — 2026-09-08 Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL reques…
CVE-2026-16005 NONE — 2026-09-08 Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verificat…
CVE-2026-16006 NONE — 2026-09-08 Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCT…
CVE-2026-82710 NONE Patched — 2026-09-08 Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control seque…
CVE-2026-82758 NONE Patched — 2026-09-07 Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client …
CVE-2026-82586 NONE Patched — 2026-09-07 Improper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list…
CVE-2026-82753 NONE Patched — 2026-09-07 Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to exhaust database st…
CVE-2026-82754 NONE Patched — 2026-09-07 Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefi…
CVE-2026-82755 NONE Patched — 2026-09-07 Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant's OAuth discovery…
CVE-2026-82756 NONE Patched — 2026-09-07 Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication …
CVE-2026-82757 NONE Patched — 2026-09-07 Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make t…
CVE-2026-81638 NONE Patched — 2026-09-07 Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.…