CVEs
Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.
229687 CVEs matched. Showing 2251–2300 (page 46 of 4594).
HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.
Click a column header to sort all results; click the active column again to reverse.
| CVE-ID ↕ | Title ↕ | Severity ↕ | Score (overview) ↕ | NVD Score | MSRC Score | CNA ↕ | Published ↕ | Remediations | Threat | Source |
|---|---|---|---|---|---|---|---|---|---|---|
CVE-2026-76974 |
Information Disclosure vulnerability in SAP Fiori Launchpad | MEDIUM | 5.3 | 5.3 | — | sap | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-94491 |
Yonyou KSOA search_list.jsp sql injection | MEDIUM | 6.9 | 7.3 | — | VulDB | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-94490 |
OctoPrint Command API system.py executeSystemCommand os command injection | MEDIUM | 5.1 | 4.7 | — | VulDB | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-88414 |
CVE-2026-88414 | — | — | — | — | mitre | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-88418 |
CVE-2026-88418 | — | — | — | — | mitre | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-79315 |
CVE-2026-79315 | — | — | 4.7 | — | mitre | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-88341 |
CVE-2026-88341 | — | — | — | — | mitre | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-75432 |
CVE-2026-75432 | — | — | — | — | mitre | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-79312 |
CVE-2026-79312 | — | — | 6.8 | — | mitre | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-88350 |
CVE-2026-88350 | — | — | — | — | mitre | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-88415 |
CVE-2026-88415 | — | — | — | — | mitre | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-79313 |
CVE-2026-79313 | — | — | 9.8 | — | mitre | 2026-09-22 | 20 | ⚠ Threat | raw · ⬇ |
CVE-2026-88345 |
CVE-2026-88345 | — | — | — | — | mitre | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-37603 |
CVE-2026-37603 | — | — | — | — | mitre | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-88416 |
CVE-2026-88416 | — | — | — | — | mitre | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-88344 |
CVE-2026-88344 | — | — | — | — | mitre | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-79311 |
CVE-2026-79311 | — | — | — | — | mitre | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-88339 |
CVE-2026-88339 | — | — | — | — | mitre | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-37604 |
CVE-2026-37604 | — | — | — | — | mitre | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-88624 |
CVE-2026-88624 | — | — | — | — | mitre | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-88419 |
CVE-2026-88419 | — | — | 8.8 | — | mitre | 2026-09-22 | 20 | ⚠ Threat | raw · ⬇ |
CVE-2026-88340 |
CVE-2026-88340 | — | — | — | — | mitre | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-79314 |
CVE-2026-79314 | — | — | — | — | mitre | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-94489 |
OctoPrint File Download API files.py _validate path traversal | MEDIUM | 5.3 | 4.3 | — | VulDB | 2026-09-21 | 10 | — | raw · ⬇ |
CVE-2026-94426 |
xuxueli xxl-job insert cross site scripting | MEDIUM | 5.1 | 3.5 | — | VulDB | 2026-09-21 | 10 | — | raw · ⬇ |
CVE-2026-94425 |
Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140006F0C privileges management | CRITICAL | 9.3 | 8.8 | — | VulDB | 2026-09-21 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94627 |
vLLM through 0.29.0 GPU KV Cache Leak via Mooncake Transfer ID Collision | HIGH | 8.7 | 7.5 | — | VulnCheck | 2026-09-21 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94626 |
vLLM through 0.29.0 Memory Exhaustion via Unvalidated NIXL tp_size | HIGH | 8.7 | 7.5 | — | VulnCheck | 2026-09-21 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94625 |
vLLM through 0.29.0 Resource Exhaustion via Ownerless Mooncake Transfer Placeholders | MEDIUM | 6.9 | 5.3 | — | VulnCheck | 2026-09-21 | 10 | — | raw · ⬇ |
CVE-2026-94624 |
vLLM through 0.29.0 Denial of Service via Unbounded P2P KV Offloading Sessions | HIGH | 8.7 | 7.5 | — | VulnCheck | 2026-09-21 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94623 |
vLLM through 0.29.0 Denial of Service via NIXL Multi-Prompt Assertion Failure | HIGH | 8.7 | 7.5 | — | VulnCheck | 2026-09-21 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94622 |
vLLM through 0.29.0 Denial of Service via Incomplete NIXL KV Transfer Metadata | HIGH | 8.7 | 7.5 | — | VulnCheck | 2026-09-21 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94540 |
DesktopSMS 1.11.0 Unauthorized Access via Local Service | HIGH | 7.4 | 7.7 | — | VulnCheck | 2026-09-21 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-65980 |
Chartbrew: SQL Injection via Missing Backslash Escaping in ClickHouse Variable Substitution | HIGH | 7.9 | — | — | GitHub_M | 2026-09-21 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-61851 |
Chartbrew: Incomplete Read-Only Keyword Blocklist in AI runQuery Tool | MEDIUM | 6.5 | — | — | GitHub_M | 2026-09-21 | 10 | — | raw · ⬇ |
CVE-2026-61852 |
Chartbrew: SQL Injection via row_limit Parameter in AI runQuery Tool | MEDIUM | 5.8 | — | — | GitHub_M | 2026-09-21 | 10 | — | raw · ⬇ |
CVE-2026-61743 |
Chartbrew: DNS Rebinding SSRF Bypass in Outbound Request Validation | MEDIUM | 6.3 | 6.3 | — | GitHub_M | 2026-09-21 | 10 | — | raw · ⬇ |
CVE-2026-94536 |
lamp-cloud through 5.10.0 Unauthorized Information Disclosure via /anyone/visible/resource | MEDIUM | 5.3 | 4.3 | — | VulnCheck | 2026-09-21 | 10 | — | raw · ⬇ |
CVE-2026-94535 |
lamp-cloud through 5.10.0 Unauthorized Notification Deletion | HIGH | 7.1 | 7.1 | — | VulnCheck | 2026-09-21 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94534 |
lamp-cloud through 5.10.0 Unauthorized Profile Modification via PUT endpoints | HIGH | 7.1 | 7.1 | — | VulnCheck | 2026-09-21 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94533 |
lamp-cloud through 5.10.0 Unauthorized File Download via /anyone/file | HIGH | 7.1 | 6.5 | — | VulnCheck | 2026-09-21 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94532 |
lamp-cloud through 5.10.0 Unauthorized User Profile Access via getUserInfoById | HIGH | 7.1 | 6.5 | — | VulnCheck | 2026-09-21 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-93340 |
Gladys Assistant < 5.1.0 Password Reset Link Poisoning via forgot_password Endpoint | HIGH | 7.4 | 6.8 | — | VulnCheck | 2026-09-21 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-61541 |
Zapros has an Unbounded Content-Encoding decompression chain that allows denial of service | MEDIUM | 6.9 | — | — | GitHub_M | 2026-09-21 | 10 | — | raw · ⬇ |
CVE-2026-59830 |
Discourse: Stored XSS via unescaped actor name in post actions | MEDIUM | 5.4 | 5.4 | — | GitHub_M | 2026-09-21 | 10 | — | raw · ⬇ |
CVE-2026-46650 |
Joplin: Stored XSS in public share viewer via javascript: URL bypass in isAcceptedUrl | MEDIUM | 4.4 | 4.4 | — | GitHub_M | 2026-09-21 | 10 | — | raw · ⬇ |
CVE-2026-17054 |
Out-of-bounds read and permanent loss of Wi-Fi reception in the ESP-hosted SPI driver's frame reassembly | MEDIUM | 5.3 | 5.3 | — | zephyr | 2026-09-21 | 10 | — | raw · ⬇ |
CVE-2026-15890 |
AEAD nonce reuse in Zephyr secure_storage ITS default nonce provider due to missing thread synchronization | MEDIUM | 5.3 | 5.3 | — | zephyr | 2026-09-21 | 10 | — | raw · ⬇ |
CVE-2026-59815 |
Joplin: Pending share recipients can write items into shared folders before accepting invitations | MEDIUM | 4.3 | 4.3 | — | GitHub_M | 2026-09-21 | 10 | — | raw · ⬇ |
CVE-2026-55210 |
Joplin: SAML SSO account takeover via email-based account linking (missing is_external check in ssoLogin) | HIGH | 7.4 | 7.4 | — | GitHub_M | 2026-09-21 | 10 | ⚠ Threat | raw · ⬇ |