Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

565 CVEs · published 2026-09-24 to 2026-09-24

CVEs (565, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 565 (capped at 500)

CVE ID Severity ↑ Patch CVSS Published Description
CVE-2026-97387 NONE — 2026-09-24 Rejected reason: This CVE is a duplicate of another CVE.
CVE-2026-97230 NONE — 2026-09-24 IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script s…
CVE-2026-85491 NONE Patched — 2026-09-24 Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request p…
CVE-2026-87720 NONE Patched — 2026-09-24 Incorrect Authorization (CWE-863) in project name normalization (ProjectUtil.stripGitSuffix) and ProjectCache eviction logic (ProjectCacheImpl) in Gerrit Code Review versio…
CVE-2026-87721 NONE Patched — 2026-09-24 Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in Gerrit Code Review versions 2.0.19 through 3.12.9, 3.13.…
CVE-2026-87722 NONE Patched — 2026-09-24 Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search query predicates (such as RegexProjectPredicate, RegexRefPredicate, RegexPathPredicate, and sibling p…
CVE-2026-97636 NONE Patched — 2026-09-24 Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag auth…
CVE-2026-88386 NONE — 2026-09-24 libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A specially crafted WAV file can cause the function to cas…
CVE-2026-88387 NONE — 2026-09-24 LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF tag 0x00fe (NewSubfileType). A specially crafted RAW, …
CVE-2026-88388 NONE — 2026-09-24 Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace handling path on 64-bit builds. A remote attacker ca…
CVE-2026-14443 NONE Patched — 2026-09-24 Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system log…
CVE-2026-14442 NONE — 2026-09-24 An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be written to application logs in plain text. When scheduled…
CVE-2026-14441 NONE — 2026-09-24 A logic flaw in Java cache key handling object comparison handling could lead to improper identifier resolution when processing specific user account structures. The issue …
CVE-2026-82372 NONE Patched — 2026-09-24 Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in appl…
CVE-2026-82371 NONE Patched — 2026-09-24 Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals with file read access to retrieve administrative switc…
CVE-2026-86857 NONE Patched — 2026-09-24 ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authe…
CVE-2026-86858 NONE Patched — 2026-09-24 ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated u…
CVE-2026-86859 NONE Patched — 2026-09-24 ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unaut…
CVE-2026-86860 NONE Patched — 2026-09-24 ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, …
CVE-2026-13016 NONE Patched — 2026-09-24 ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certa…
CVE-2026-61742 NONE — 2026-09-24 DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose an unauthenticated HTTP MCP endpoint when started w…
CVE-2026-61604 NONE Patched — 2026-09-24 The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds module moved funds from an address that was resolved f…
CVE-2026-97521 NONE — 2026-09-24 In the Linux kernel, the following vulnerability has been resolved: gfs2: fix quota init duplicate scan gfs2_quota_init() checks for duplicate quota_change IDs while hold…
CVE-2026-97512 NONE — 2026-09-24 In the Linux kernel, the following vulnerability has been resolved: spi: spi-qcom-qspi: Fix incomplete error handling in runtime PM The runtime PM functions had incomplet…
CVE-2026-97514 NONE — 2026-09-24 In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Fix Reports from Kernel Lock Validator handle_dynamic_resolution change req…