Search
790 CVEs · Medium severity
CVEs (790, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 790 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86550 | MEDIUM | 6.5 | 2026-09-08 | NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This resul… | |
| CVE-2026-86597 | MEDIUM | 6.5 | 2026-09-08 | Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encrypti… | |
| CVE-2026-74859 | MEDIUM | 6.8 | 2026-09-08 | The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files … | |
| CVE-2026-62652 | MEDIUM | 5.3 | 2026-09-08 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from which debugging symbols have not been removed. This … | |
| CVE-2026-62653 | MEDIUM | 6.8 | 2026-09-08 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The input received over a proprietary communication protocol that is exposed when the device is… | |
| CVE-2026-62654 | MEDIUM | 6.8 | 2026-09-08 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated via a physical key sequence during device boot, in … | |
| CVE-2026-58113 | MEDIUM | 6.1 | 2026-09-08 | A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.26… | |
| CVE-2026-81802 | MEDIUM | 6.5 | 2026-09-08 | Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions. | |
| CVE-2026-81792 | MEDIUM | 6.5 | 2026-09-08 | Unauthenticated Privilege Escalation in Product Catalog Enquiry for WooCommerce by MultiVendorX <= 6.1.4 versions. | |
| CVE-2026-86519 | MEDIUM | 5.3 | 2026-09-08 | A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handle… | |
| CVE-2026-86516 | MEDIUM | 4.7 | 2026-09-08 | A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-… | |
| CVE-2026-86517 | MEDIUM | 6.3 | 2026-09-08 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a man… | |
| CVE-2026-86518 | MEDIUM | 6.3 | 2026-09-08 | A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument ID lead… | |
| CVE-2026-86511 | MEDIUM | 5.3 | 2026-09-08 | A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal.toPlainString of the file src/main/java/com/gi… | |
| CVE-2026-86512 | MEDIUM | 6.3 | 2026-09-08 | A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/git… | |
| CVE-2026-86513 | MEDIUM | 5.3 | 2026-09-08 | A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/… | |
| CVE-2026-86514 | MEDIUM | 6.3 | 2026-09-08 | A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation ca… | |
| CVE-2026-86515 | MEDIUM | 4.3 | 2026-09-08 | A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such manip… | |
| CVE-2026-76963 | MEDIUM | 4.3 | 2026-09-08 | Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive sy… | |
| CVE-2026-76968 | MEDIUM | 6.5 | 2026-09-08 | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or … | |
| CVE-2026-76971 | MEDIUM | 6.5 | 2026-09-08 | Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbou… | |
| CVE-2026-76977 | MEDIUM | 4.3 | 2026-09-08 | SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing… | |
| CVE-2026-76959 | MEDIUM | 4.6 | 2026-09-08 | SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low pri… | |
| CVE-2026-76962 | MEDIUM | 4.3 | 2026-09-08 | SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send spec… | |
| CVE-2026-44766 | MEDIUM | 6.5 | 2026-09-08 | SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed b… |