CVEs
Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.
229687 CVEs matched. Showing 1951–2000 (page 40 of 4594).
HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.
Click a column header to sort all results; click the active column again to reverse.
| CVE-ID ↕ | Title ↕ | Severity ↕ | Score (overview) ↕ | NVD Score | MSRC Score | CNA ↕ | Published ↕ | Remediations | Threat | Source |
|---|---|---|---|---|---|---|---|---|---|---|
CVE-2026-75649 |
Bridge | Heap-based Buffer Overflow (CWE-122) | HIGH | 7.8 | 7.8 | — | adobe | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-75676 |
Bridge | Stack-based Buffer Overflow (CWE-121) | HIGH | 7.8 | 7.8 | — | adobe | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-75655 |
Bridge | Uncontrolled Recursion (CWE-674) | HIGH | 7.8 | 7.8 | — | adobe | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-75665 |
Bridge | Heap-based Buffer Overflow (CWE-122) | HIGH | 7.8 | 7.8 | — | adobe | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-75663 |
Bridge | Out-of-bounds Write (CWE-787) | HIGH | 7.8 | 7.8 | — | adobe | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77246 |
MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path | HIGH | 7.4 | 7.4 | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-75632 |
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) | HIGH | 7.5 | 7.5 | — | adobe | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-75634 |
CAI Content Credentials | Improper Input Validation (CWE-20) | MEDIUM | 4.3 | 4.3 | — | adobe | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-75633 |
CAI Content Credentials | Improper Input Validation (CWE-20) | MEDIUM | 5.5 | 5.5 | — | adobe | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-19480 |
CAI Content Credentials | Improper Input Validation (CWE-20) | HIGH | 7.5 | 7.5 | — | adobe | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-89277 |
CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) | MEDIUM | 5.5 | 5.5 | — | adobe | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-75638 |
CAI Content Credentials | Improper Input Validation (CWE-20) | MEDIUM | 6.5 | 6.5 | — | adobe | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-76194 |
CAI Content Credentials | Improper Input Validation (CWE-20) | MEDIUM | 4.3 | 4.3 | — | adobe | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-77248 |
MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on s… | HIGH | 8.6 | 8.6 | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95862 |
CVE-2026-95862 | HIGH | 7.5 | 7.5 | — | Ubiquiti | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77256 |
MCP Atlassian: OAuth refresh-token backup file is world-readable under default Unix umask | HIGH | 8.3 | — | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95861 |
CVE-2026-95861 | HIGH | 7.5 | 7.5 | — | Ubiquiti | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77249 |
MCP Atlassian: Incomplete fix for CVE-2026-27826: redirect-based SSRF via unhooked requests session in Jira user-permiss… | MEDIUM | 5.3 | 5.3 | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-77259 |
MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials | HIGH | 7.7 | 7.7 | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77268 |
MCP Atlassian: Insecure File Permissions on OAuth Token Storage | MEDIUM | 5.5 | 5.5 | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-77558 |
CVE-2026-77558 | HIGH | 7.5 | 7.5 | — | Ubiquiti | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77556 |
CVE-2026-77556 | HIGH | 7.5 | 7.5 | — | Ubiquiti | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77555 |
CVE-2026-77555 | HIGH | 7.5 | 7.5 | — | Ubiquiti | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77544 |
CVE-2026-77544 | HIGH | 7.5 | 7.5 | — | Ubiquiti | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77247 |
MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters | HIGH | 8.3 | — | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-84396 |
InDesign Desktop | NULL Pointer Dereference (CWE-476) | MEDIUM | 5.5 | 5.5 | — | adobe | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-76192 |
InDesign Desktop | NULL Pointer Dereference (CWE-476) | MEDIUM | 5.5 | 5.5 | — | adobe | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-77272 |
MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler | MEDIUM | 5.4 | 5.4 | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-77269 |
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825) | MEDIUM | 6.5 | 6.5 | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-77266 |
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call | MEDIUM | 6.5 | 6.5 | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-77255 |
MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue | HIGH | 8.6 | 8.6 | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95831 |
Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfu… | — | — | 7.8 | — | CPANSec | 2026-09-22 | 20 | ⚠ Threat | raw · ⬇ |
CVE-2026-77262 |
MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of CVE-2026… | HIGH | 8.6 | 8.6 | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77254 |
MCP Atlassian: Unauthenticated HTTP MCP requests can use globally configured Jira and Confluence credentials | CRITICAL | 9.1 | 9.1 | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77253 |
MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files | HIGH | 7.1 | 7.1 | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77257 |
MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths | HIGH | 8.3 | — | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77261 |
MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches | HIGH | 7.1 | 7.1 | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77260 |
MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira) | HIGH | 8.3 | — | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77271 |
MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of CVE-2026-27825) | HIGH | 8.3 | — | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95660 |
Moonshot AI Kimi Code MCP Configuration Loader config-loader.ts os command injection | MEDIUM | 5.3 | 6.3 | — | VulDB | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-77242 |
MCP Atlassian: Incomplete fix for CVE-2026-27826: DNS rebinding bypasses SSRF validation (validated IP not pinned) | HIGH | 7.5 | 7.5 | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77243 |
MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass | HIGH | 8.8 | 8.8 | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77251 |
MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-pr… | HIGH | 8.3 | — | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-43643 |
Softaculous Virtualizor Authorization Bypass via Billing Module Handler | HIGH | 8.7 | 7.5 | — | VulnCheck | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77252 |
MCP Atlassian: JIRA_PROJECTS_FILTER and CONFLUENCE_SPACES_FILTER can be bypassed in search tools | MEDIUM | 6.5 | 6.5 | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-43642 |
Softaculous Virtualizor PHP Object Injection via Billing Module Handler | CRITICAL | 9.2 | 8.1 | — | VulnCheck | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77267 |
mcp-atlassian has an incomplete SSRF remediation | HIGH | 8.3 | — | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-43641 |
Softaculous Virtualizor OS Command Injection via Billing Module Handler | CRITICAL | 9.3 | 9.8 | — | VulnCheck | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77250 |
MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions | MEDIUM | 6.1 | 6.1 | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-18626 |
Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. | MEDIUM | 6.8 | — | — | RTI | 2026-09-22 | 10 | — | raw · ⬇ |