CVEs
Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.
229687 CVEs matched. Showing 2051–2100 (page 42 of 4594).
HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.
Click a column header to sort all results; click the active column again to reverse.
| CVE-ID ↕ | Title ↕ | Severity ↕ | Score (overview) ↕ | NVD Score | MSRC Score | CNA ↕ | Published ↕ | Remediations | Threat | Source |
|---|---|---|---|---|---|---|---|---|---|---|
CVE-2026-13087 |
Kernel: heap out-of-bounds write in the linux kernel rpc-over-rdma server reply path... | HIGH | 8.8 | 8.8 | — | redhat | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-84301 |
FastGPT safe axios SSRF guard still allows DNS rebinding TOCTOU on protected outbound requests | MEDIUM | 6.3 | 6.3 | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-95818 |
AT_SECURE program buffer overflow via $ORIGIN processing | LOW | 3.6 | 3.6 | 3.6 | glibc | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-76805 |
Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode | MEDIUM | 5.3 | 5.3 | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-76802 |
Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass | MEDIUM | 4.7 | 4.7 | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-87902 |
CVE-2026-87902 | — | — | 8.1 | — | hackerone | 2026-09-22 | 12 | ⚠ Threat | raw · ⬇ |
CVE-2026-76819 |
CVE-2026-76819 | — | — | — | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-76804 |
Nuclei: Local File Read via Workflow File-Protocol Gate Bypass | MEDIUM | 5.5 | 5.5 | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-76803 |
Nuclei: Local File Read via MySQL Client Sandbox Bypass | MEDIUM | 5.3 | 5.3 | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-83803 |
Sentry: Unsafe pickle deserialization in Relocation Feature | HIGH | 7.7 | — | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-86062 |
LightRAG: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content | MEDIUM | 6.1 | 6.1 | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-85740 |
LightRAG: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download g… | HIGH | 7.1 | 7.1 | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-85734 |
LightRAG: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks | CRITICAL | 9.1 | 9.1 | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94455 |
Unauthenticated /enterprise/create-user mints lifetime top-tier organizations and discloses their API key | HIGH | 7.1 | 7.1 | — | postiz | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-85725 |
LightRAG: Plaintext Passwords Compared Without Constant-Time Function | MEDIUM | 5.9 | 5.9 | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-85709 |
LightRAG: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses | MEDIUM | 5.3 | 5.3 | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-86059 |
Dokploy: Git Provider Credential Exposure via Unprotected .one Endpoints and application.one | CRITICAL | 9.6 | 9.6 | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94456 |
Unauthenticated recovery of the Math.random() state behind OAuth tokens, authorization codes, client secrets and organiz… | CRITICAL | 9.1 | 9.1 | — | postiz | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-56682 |
9Router: Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header | MEDIUM | 5.3 | 5.3 | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-56681 |
9Router: Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header | HIGH | 7.3 | 7.3 | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-86805 |
AT_SECURE programs may load attacker-controlled code via $ORIGIN | MEDIUM | 6.3 | 6.3 | 6.3 | glibc | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-86698 |
Refresh tokens accepted as private repository credentials at the CDN | LOW | 2.3 | — | — | EEF | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-75517 |
Novu: Cross-Environment Integration Manipulation (IDOR) | MEDIUM | 6.5 | 6.5 | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-90462 |
Sssd: sssd: fail-open in ldap ppolicy access check allows continued authorization | MEDIUM | 5.4 | 5.4 | — | redhat | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-75511 |
Novu: Server-Side Request Forgery (SSRF) via Chat Provider Webhook URLs | MEDIUM | 5.3 | — | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-75510 |
Novu: Stored XSS in In-App Inbox via notification redirect.url javascript: scheme | MEDIUM | 5.1 | — | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-94640 |
Rpcbind: unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of service | HIGH | 7.5 | 7.5 | — | redhat | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-70410 |
Apache Calcite Avatica: Unrestricted class initialization when instantiating plugins | — | — | 8.8 | — | apache | 2026-09-22 | 20 | ⚠ Threat | raw · ⬇ |
CVE-2026-88010 |
Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle | MEDIUM | 6.3 | — | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-75608 |
Frigate: Viewer-Role User Can Access go2rtc Internal API to obtain sensitive information | HIGH | 7.7 | 7.7 | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-75607 |
Frigate: WebSocket Missing Authorization — Viewer Can Execute Admin-Only Operations | HIGH | 8.1 | 8.1 | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77637 |
Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope | LOW | 3.8 | 3.8 | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-77633 |
Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service | HIGH | 7.1 | 7.1 | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-79913 |
Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching i… | MEDIUM | 6.5 | 6.5 | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-95655 |
Aureus ERP before 1.5.0 Unscoped Message Access via ChatterPanel | HIGH | 8.6 | 8.1 | — | VulnCheck | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95654 |
Databasement before 1.7.14 Authorization Bypass via Stale Invitation Token | CRITICAL | 9.1 | 7.4 | — | VulnCheck | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95653 |
Concrete CMS Community Store before 2.7.8 Predictable Digital Download Token | HIGH | 8.7 | 7.5 | — | VulnCheck | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-80156 |
Lantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload Filename Validation Bypass | CRITICAL | 9.4 | 9.1 | — | VulnCheck | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-63374 |
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing | CRITICAL | 9.3 | — | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-80155 |
Lantronix Autonomous Out-of-Band Devices Unauthenticated Authentication Bypass via snprintf Path Truncation | CRITICAL | 10.0 | 10.0 | — | VulnCheck | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-80154 |
Lantronix Autonomous Out-of-Band Devices Predictable Session Token with Validation Bypass | HIGH | 8.9 | 9.6 | — | VulnCheck | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-80152 |
Lantronix Autonomous Out-of-Band Devices OS Command Injection via set script schedule | CRITICAL | 9.4 | 9.1 | — | VulnCheck | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-92706 |
Dark Reader: Ability to request icon-like bitmap data from certain local web servers | LOW | 3.4 | 3.4 | — | GitHub_M | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-80151 |
Lantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs download | CRITICAL | 9.4 | 9.1 | — | VulnCheck | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-80150 |
Lantronix Autonomous Out-of-Band Devices WebTelnet SSRF via rooturl Parameter | HIGH | 7.7 | 7.5 | — | VulnCheck | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-80149 |
Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via rooturl Parameter | HIGH | 7.7 | 8.6 | — | VulnCheck | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-80148 |
Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via Username Truncation | HIGH | 7.7 | 8.6 | — | VulnCheck | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-85055 |
Twenty: Field-level read bypass | HIGH | 7.1 | — | — | GitHub_M | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-80147 |
Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom write | CRITICAL | 9.4 | 9.9 | — | VulnCheck | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-80146 |
Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom read | CRITICAL | 9.4 | 9.9 | — | VulnCheck | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |