CVEs
Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.
228318 CVEs matched. Showing 201–250 (page 5 of 4567).
HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.
Click a column header to sort all results; click the active column again to reverse.
| CVE-ID ↕ | Title ↕ | Severity ↕ | Score (overview) ↕ | NVD Score | MSRC Score | CNA ↕ | Published ↕ | Remediations | Threat | Source |
|---|---|---|---|---|---|---|---|---|---|---|
CVE-2026-71459 |
Automation-controller: automation-controller-container: automation-controller: jobjobeventschildrensummary … | MEDIUM | 5.0 | 5.0 | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-71458 |
Automation-controller: automation-controller-container: automation-controller: named-url 404 body oracle enables cross-t… | MEDIUM | 5.0 | 5.0 | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-77421 |
JLine: ReDoS in Nano Editor Regex Search Mode | MEDIUM | 6.5 | 6.5 | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-92730 |
LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name | HIGH | 7.4 | — | — | Fluid Attacks | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-63132 |
OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack | CRITICAL | 9.2 | — | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-63131 |
OpenBao LIST ACL bypass: a trailing-slash LIST request skips a more-specific deny rule (unported Vault v2.0.3 fix) | MEDIUM | 6.0 | — | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-77285 |
OpenBao Agent Writes Secrets to Stdout | LOW | 2.4 | — | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-55632 |
GoCD is vulnerable to authorization bypass via pipeline structure API | MEDIUM | 4.3 | 4.3 | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-52744 |
GoCD is vulnerable to authorization bypass via fetch artifact autosuggestion API | MEDIUM | 5.3 | — | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-92700 |
Caddy: fileHidden() case-sensitive pattern bypass — exposes "hidden" files via case variation | MEDIUM | 6.3 | — | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-92284 |
Caddy: Unbounded body buffer via {http.request.body} placeholder — memory exhaustion DoS | MEDIUM | 6.9 | — | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-88840 |
Busybox: busybox: tls ssl_server reads one byte out of bounds when parsing truncated clienthello | MEDIUM | 5.3 | 5.3 | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-88839 |
Busybox: busybox: passwd/group parser writes heap pointers out of bounds due to stale tokenize() endpoint | MEDIUM | 6.7 | 6.7 | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-88837 |
Busybox: busybox: httpd misidentifies yescrypt password hashes as plaintext, inverting authentication | MEDIUM | 6.5 | 6.5 | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-88835 |
Busybox: busybox: dpkg read_package_field() steps past nul terminator, causing out-of-bounds read on malformed .deb pack… | MEDIUM | 6.1 | — | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-88831 |
Busybox: busybox: httpd silently fails open when ip deny rules contain invalid cidr prefix lengths | MEDIUM | 5.3 | 5.3 | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-86867 |
Cinnamon's kotaemon contains improper authorization checks in multi‑user chat handlers | — | — | — | — | certcc | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-86934 |
CVE-2026-86934 | — | — | — | — | apple | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-86938 |
CVE-2026-86938 | — | — | — | — | apple | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-86926 |
CVE-2026-86926 | — | — | — | — | apple | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-86930 |
CVE-2026-86930 | — | — | — | — | apple | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-91775 |
LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS survey-import warnings | HIGH | 7.4 | — | — | Fluid Attacks | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-88832 |
Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label buffer, causing heap overflow | HIGH | 7.3 | — | — | redhat | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-88830 |
Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pre-auth heap buffer overflow | HIGH | 7.5 | 7.5 | — | redhat | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96808 |
CVE-2026-96808 | HIGH | 7.4 | 7.4 | — | mitre | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96807 |
CVE-2026-96807 | MEDIUM | 4.0 | 4.0 | — | mitre | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-96514 |
Neethuharii CafeManagement Login CafePortalLogin.php sql injection | MEDIUM | 6.9 | 7.3 | — | VulDB | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-96804 |
CVE-2026-96804 | — | — | 8.8 | — | certcc | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-93349 |
Frictionless OS Command Injection via explore Console Command | HIGH | 8.6 | 8.8 | — | VulnCheck | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96513 |
Neethuharii CafeManagement AddProductCode.php unrestricted upload | MEDIUM | 6.9 | 7.3 | — | VulDB | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-95848 |
Moquette fails open when configured authentication or authorization classes cannot load | CRITICAL | 9.3 | — | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95847 |
Moquette client IDs can cause cross-session H2 durable-queue corruption | HIGH | 8.8 | — | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95846 |
Moquette publishes Last-Will messages without enforcing write authorization | HIGH | 8.7 | — | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95845 |
Moquette unbounded per-session message queues allow memory exhaustion | HIGH | 8.7 | — | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95844 |
Moquette deeply nested MQTT topics can cause stack exhaustion | HIGH | 8.7 | — | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95843 |
Moquette malformed shared subscriptions can crash command processing | HIGH | 8.7 | — | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95842 |
Moquette uncaught MQTT command exceptions can terminate shared session event loops | HIGH | 8.7 | — | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-85724 |
Moquette pattern ACL wildcard injection allows cross-tenant authorization bypass | CRITICAL | 9.6 | 9.6 | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96775 |
MLflow dspy bypasses pickle deserialization control | — | — | 8.8 | — | certcc | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-96759 |
orval before 8.29.0 Code Injection via operationId | CRITICAL | 9.3 | 9.8 | — | VulnCheck | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96758 |
orval @orval/core before 8.28.0 Code Injection via Form-Data | CRITICAL | 9.3 | 9.8 | — | VulnCheck | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96757 |
orval before 8.29.0 Code Injection via unescaped OpenAPI media-type | CRITICAL | 9.3 | 9.8 | — | VulnCheck | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96756 |
orval before 8.30.0 Code Injection via Factory Generation | CRITICAL | 9.2 | 8.1 | — | VulnCheck | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96755 |
orval @orval/effect 8.14.0 through 8.28.1 Code Injection | CRITICAL | 9.3 | 9.8 | — | VulnCheck | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96754 |
orval @orval/hono before 8.29.0 Code Injection via OpenAPI Path | CRITICAL | 9.3 | 9.8 | — | VulnCheck | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-96656 |
Plex Media Server arbitrary file write | HIGH | 8.6 | 7.2 | — | cisa-cg | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96655 |
Plex Media Server arbitrary-host SSRF | MEDIUM | 5.3 | 4.3 | — | cisa-cg | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-96654 |
Plex Media Server URL injection | MEDIUM | 6.9 | 6.5 | — | cisa-cg | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-96652 |
Plex Media Server SSRF | MEDIUM | 5.3 | 4.3 | — | cisa-cg | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-96651 |
Plex Media Server path traversal | HIGH | 7.1 | 6.5 | — | cisa-cg | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |