CVEs
Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.
229687 CVEs matched. Showing 2151–2200 (page 44 of 4594).
HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.
Click a column header to sort all results; click the active column again to reverse.
| CVE-ID ↕ | Title ↕ | Severity ↕ | Score (overview) ↕ | NVD Score | MSRC Score | CNA ↕ | Published ↕ | Remediations | Threat | Source |
|---|---|---|---|---|---|---|---|---|---|---|
CVE-2026-24239 |
CVE-2026-24239 | HIGH | 7.8 | 7.8 | — | nvidia | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-24267 |
CVE-2026-24267 | HIGH | 7.8 | 7.8 | — | nvidia | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-93344 |
MarketKing < 2.1.72 Missing Authorization via marketking_get_page_content AJAX | HIGH | 7.1 | 6.5 | — | VulnCheck | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-93343 |
MarketKing < 2.1.72 Missing Authorization via marketking_admin_vendors_ajax | HIGH | 7.1 | 6.5 | — | VulnCheck | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95682 |
MISP Stored Cross-Site Scripting via Unescaped Organization Name in Admin Email View | MEDIUM | 4.8 | — | — | CIRCL | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-93342 |
MarketKing < 2.1.72 Missing Authorization via marketking_duplicate_product AJAX | MEDIUM | 5.3 | 5.4 | — | VulnCheck | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-12718 |
SQLi in Karel Electronics' KarelIPS | CRITICAL | 9.8 | 9.8 | — | TR-CERT | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-93341 |
MarketKing < 2.1.72 Missing Authorization via marketking_send_refund AJAX | MEDIUM | 5.3 | 4.3 | — | VulnCheck | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-95679 |
MISP Unauthenticated Blind SSRF via XML Body Processing | MEDIUM | 6.9 | — | — | CIRCL | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-95675 |
D-Link DAP-1360 6.14 Unauthenticated RCE via Web Management Interface | CRITICAL | 9.3 | 9.8 | — | VulnCheck | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95499 |
JosephChuks php-file-manager-with-code-editor filemanager.php move_uploaded_file unrestricted upload | MEDIUM | 6.9 | 7.3 | — | VulDB | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-95674 |
MISP EventsController queryEnrichment allows querying unavailable or legacy modules without validation | MEDIUM | 5.3 | — | — | CIRCL | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-95671 |
MISP Collections: Missing Authorization Check for Sharing Group on PUT Request in collections/add | MEDIUM | 5.3 | — | — | CIRCL | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-95667 |
MISP Installer Log and FIFO Created World-Readable, Exposing Sensitive Credentials | MEDIUM | 6.9 | — | — | CIRCL | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-95666 |
Unbounded post ID array in the bulk reactions endpoint allows denial of service | MEDIUM | 4.3 | 4.3 | — | Mattermost | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-95665 |
MISP Reflected Cross-Site Scripting in Event Export Confirmation Form via Unescaped JSON | MEDIUM | 5.1 | — | — | CIRCL | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-95396 |
sfturing hosp_order Public Search Handlers HospitalController.java cross site scripting | MEDIUM | 5.3 | 4.3 | — | VulDB | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-93616 |
Directory Traversal and File upload allows execution of arbitrary script on the Management Server | CRITICAL | 9.8 | 9.8 | — | checkpoint | 2026-09-22 | 1 | ⚠ Threat | raw · ⬇ |
CVE-2026-95661 |
MISP Reflected Cross-Site Scripting in Attribute Histogram via Unescaped URL-Supplied Type List | MEDIUM | 5.1 | — | — | CIRCL | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-95619 |
Gcc: libstdc++ integer overflow in `new` operator | HIGH | 7.7 | 7.7 | — | redhat | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95659 |
MISP Reflected XSS via Unvalidated Object Type in AnalystData Overmind Thread | MEDIUM | 4.8 | — | — | CIRCL | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-95658 |
MISP CSRF vulnerability in workflow moduleStatelessExecution allows cross-site execution of workflow modules | MEDIUM | 6.9 | — | — | CIRCL | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-95273 |
dgtlmoon changedetection.io visual_selector_data flask_app.py static_content path traversal | MEDIUM | 5.3 | 4.3 | — | VulDB | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-95272 |
dgtlmoon changedetection.io Screenshot flask_app.py static_content path traversal | MEDIUM | 6.3 | 3.7 | — | VulDB | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-75791 |
Authentication bypass vulnerability | HIGH | 8.6 | 8.6 | — | Zohocorp | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95271 |
dgtlmoon changedetection.io Authentication Hook flask_app.py check_authentication improper authentication | MEDIUM | 6.9 | 7.3 | — | VulDB | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-74849 |
Remote code execution vulnerability | CRITICAL | 9.8 | 9.8 | — | Zohocorp | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-87119 |
mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credentia… | HIGH | 8.2 | — | — | EEF | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-89420 |
Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free | HIGH | 7.1 | — | — | EEF | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95270 |
dgtlmoon changedetection.io Hash Comparison flask_app.py check_password timing discrepancy | MEDIUM | 6.3 | 3.7 | — | VulDB | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-63279 |
Out of bounds read in PICT image import | MEDIUM | 5.4 | — | — | Document Fdn. | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-63278 |
Package URLs can be used to exfiltrate arbitrary INI file values and environment variables | MEDIUM | 6.7 | — | — | Document Fdn. | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-63276 |
Stack buffer overflow in CFF to Type 1 font conversion | MEDIUM | 5.4 | — | — | Document Fdn. | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-63275 |
Stack buffer overflow in CFF font hint handling | MEDIUM | 5.4 | — | — | Document Fdn. | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-63274 |
Heap buffer overflow in PDF import stream handling | MEDIUM | 5.4 | — | — | Document Fdn. | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-63273 |
Heap buffer overflow in PDF import encryption handling | MEDIUM | 5.4 | — | — | Document Fdn. | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-63272 |
Heap buffer overflow in WMF text record import | MEDIUM | 5.4 | — | — | Document Fdn. | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-95623 |
Tauri framework v2 SSRF Protection Bypass via HTTP Redirects | MEDIUM | 5.6 | 5.6 | — | JFROG | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-90990 |
Livestatus injection via monitoring filter values | MEDIUM | 5.3 | — | — | Checkmk | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-92882 |
Redact SNMP community, SNMPv3 pass phrases, and IPMI password in host config REST API GET responses | LOW | 2.3 | — | — | Checkmk | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-25265 |
Creation of Temporary File with Insecure Permissions in Qualcomm Software Center | HIGH | 8.8 | 8.8 | — | qualcomm | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-25264 |
Uncontrolled Search Path Element in Qualcomm Software Center | HIGH | 8.8 | 8.8 | — | qualcomm | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-25262 |
Write-what-where Condition in Primary Bootloader | MEDIUM | 6.9 | 6.9 | — | qualcomm | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-25255 |
Exposed function in Qualcomm Package Manager and Qualcomm Software Center. | HIGH | 8.8 | 8.8 | — | qualcomm | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-25254 |
Improper authorization in Qualcomm Software Center | CRITICAL | 9.8 | 9.8 | — | qualcomm | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-90882 |
Reflected arbitrary origins with credentials, allowing cross-origin reads of authenticated user data | HIGH | 8.7 | — | — | eclipse | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94117 |
WordPress HashBar – WordPress Notification Bar plugin <= 2.0.3 - SQL Injection vulnerability | HIGH | 7.6 | 7.6 | — | Patchstack | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-93556 |
Direct references to unsafe objects (IDOR) in Tankuam Places by Kompini | CRITICAL | 9.3 | — | — | INCIBE | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-65634 |
Superlinear CPU denial of service in Erlang/OTP ASN.1 OBJECT IDENTIFIER decoder | HIGH | 8.2 | — | — | EEF | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-68956 |
SSH daemon allocates unbounded idle session channels, bypassing max_channels | HIGH | 7.1 | — | — | EEF | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |