Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
36,134 matching · page 75/723Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-50719(opens NVD record) | Medium | 6.8 | The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from the SPL header before checking the secure boot state and before invoking signature verification. The init table parser supports full-address 32-bit write operations, allowing modification of SRAM-resident secure boot state prior to the verification decision. An attacker with physical write access to boot media can inject an init-table entry that disables the secure boot check, causing the ROM to accept unsigned or modified first-stage boot code. This has been hardware-validated on a secureboot-enabled T41 device; ROM analysis confirms closely related behavior on T32, T40, and A1. | Aug 19, 2026 |
| CVE-2026-43961(opens NVD record) | High | 7.8 | A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim. | Aug 19, 2026 |
| CVE-2026-16019(opens NVD record) | Critical | 9.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows SQL Injection. This issue affects FAYDAM Datalogger: from 2.7.1 before 2.8.0. | Aug 19, 2026 |
| CVE-2024-58376(opens NVD record) | High | 8.8 | Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary commands. Attackers can manipulate registryAliases keys with unquoted shell metacharacters to inject commands executed during helm repo add operations, gaining full access to Renovate's execution environment. | Aug 19, 2026 |
| CVE-2020-37267(opens NVD record) | High | 7.5 | Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION parameter is logged without redaction. Anyone with access to saved logs could obtain the bot credentials. Fixed in 23.25.1; Azure DevOps users should revoke and regenerate credentials if logs may have been exposed. | Aug 19, 2026 |
| CVE-2019-25766(opens NVD record) | High | 7.5 | Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Modules update failure scenarios. The issue is fixed in version 19.38.7. Anyone able to view the affected pull request comments could obtain the exposed tokens. | Aug 19, 2026 |
| CVE-2026-76235(opens NVD record) | High | 7.5 | A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service. | Aug 19, 2026 |
| CVE-2026-73394(opens NVD record) | High | 7.5 | Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions. | Aug 19, 2026 |
| CVE-2026-73391(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. | Aug 19, 2026 |
| CVE-2026-73390(opens NVD record) | Critical | 9.8 | Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. | Aug 19, 2026 |
| CVE-2026-73389(opens NVD record) | Critical | 9.8 | Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. | Aug 19, 2026 |
| CVE-2026-73388(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions. | Aug 19, 2026 |
| CVE-2026-73387(opens NVD record) | High | 8.1 | Unauthenticated Local File Inclusion in Resido <= 1.5 versions. | Aug 19, 2026 |
| CVE-2026-73386(opens NVD record) | High | 7.5 | Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions. | Aug 19, 2026 |
| CVE-2026-73385(opens NVD record) | High | 7.5 | Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions. | Aug 19, 2026 |
| CVE-2026-73384(opens NVD record) | High | 7.5 | Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions. | Aug 19, 2026 |
| CVE-2026-73364(opens NVD record) | Critical | 9.8 | Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions. | Aug 19, 2026 |
| CVE-2026-73363(opens NVD record) | Medium | 6.5 | Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions. | Aug 19, 2026 |
| CVE-2026-73354(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions. | Aug 19, 2026 |
| CVE-2026-73347(opens NVD record) | Critical | 9.8 | Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions. | Aug 19, 2026 |
| CVE-2026-73185(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions. | Aug 19, 2026 |
| CVE-2026-73184(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions. | Aug 19, 2026 |
| CVE-2026-73183(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. | Aug 19, 2026 |
| CVE-2026-73182(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions. | Aug 19, 2026 |
| CVE-2026-67364(opens NVD record) | Unscored | — | Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted with the raw, unescaped value of a query parameter, letting an unauthenticated attacker inject arbitrary PHP that executes server-side. The CSRF token needed to reach the endpoint is itself disclosed anonymously via a separate task, so it provides no real protection. Exploitability requires the form to have a custom-PHP handler configured (a documented builder feature) referencing that shortcode, and no reCAPTCHA on the submit button. | Aug 19, 2026 |
| CVE-2026-67363(opens NVD record) | Unscored | — | Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward it to the payment gateway without recomputing it from the form's configured product prices. Neither endpoint enforces authentication or CSRF checks. An unauthenticated attacker can purchase any priced item for an arbitrary amount (e.g., $0.01), and can additionally forge line items, quantities, and shipping. | Aug 19, 2026 |
| CVE-2026-66668(opens NVD record) | High | 8.5 | Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions. | Aug 19, 2026 |
| CVE-2026-66613(opens NVD record) | Critical | 9.8 | Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions. | Aug 19, 2026 |
| CVE-2026-66596(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions. | Aug 19, 2026 |
| CVE-2026-61986(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions. | Aug 19, 2026 |
| CVE-2026-32552(opens NVD record) | High | 8.5 | Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions. | Aug 19, 2026 |
| CVE-2026-19490(opens NVD record) | Unscored | — | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21. | Aug 19, 2026 |
| CVE-2026-19489(opens NVD record) | Unscored | — | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21. | Aug 19, 2026 |
| CVE-2026-18372(opens NVD record) | Unscored | — | CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated vault administrator to inject arbitrary CSS, affecting the web user interface displayed to other vault users. | Aug 19, 2026 |
| CVE-2026-18371(opens NVD record) | Unscored | — | HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to affect web user interface contents displayed to other users. | Aug 19, 2026 |
| CVE-2026-16440(opens NVD record) | Unscored | — | In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deeply nested annotations causes a segmentation fault. | Aug 19, 2026 |
| CVE-2026-76166(opens NVD record) | Medium | 4.3 | A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single crafted UDP multicast datagram with a valid HTTP status line and a "Server:" header but without the "Date:", "Digest:", and "Sequence:" headers triggers a NullPointerException in verifyDigest() that is not caught by the worker thread's exception handler. This causes the advertise listener thread to terminate permanently. The failure is silent (isListening() continues to return true) and persists until the node is restarted. The crash occurs before the AdvertiseSecurityKey comparison, so deployments with a configured security key are still affected. | Aug 19, 2026 |
| CVE-2026-76164(opens NVD record) | Unscored | — | AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission functionality. A low-privileged authenticated user with access to the crawler interface can submit an arbitrary URL for crawling without adequate validation of the destination host. The crawler can therefore be instructed to make direct HTTP(S) requests to addresses that should not be reachable by application users, including loopback addresses, RFC1918 private networks, link-local addresses, and cloud metadata services such as 169.254.169.254. Manual crawler tasks bypass the existing domain blacklist because they are assigned a non-zero priority, and ordinary IP literals are classified as web targets and fetched directly rather than through Tor or another proxy. Consequently, an attacker can use the AIL server as a network pivot to access services available from the server's network context. Responses generated by these requests, including captured HTML, screenshots, and HAR data, can subsequently be accessed through the crawler interface. This makes the SSRF non-blind and may allow an attacker to disclose sensitive internal application data, service information, or cloud instance metadata and credentials. The patch introduces validation that resolves crawler destinations and rejects URLs resolving to non-global IP addresses, addressing localhost, private-network, and link-local targets. | Aug 19, 2026 |
| CVE-2026-75900(opens NVD record) | Medium | 6.1 | An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the buffer length against sizeof(bh), where bh is a pointer, instead of sizeof(*bh), the actual struct size. This allows an undersized buffer to pass validation, causing a 2-byte heap overread on 64-bit systems (6 bytes on 32-bit) when accessing the totlen field. This may cause daemon termination on some platforms and leaks heap data to the log. | Aug 19, 2026 |
| CVE-2026-75589(opens NVD record) | High | 7.5 | Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. Each of the three compares the signature carried in the message against the locally computed one with the eq operator, which returns as soon as the two strings differ. The time taken to reject a signature varies with the length of the matching prefix. RSA-SHA1 is not affected, as it verifies through the RSA key object rather than by comparing strings. A client that can submit messages and time the replies may recover a valid signature one byte at a time rather than searching the whole signature space. Under PLAINTEXT the value compared against is the signature key itself, so the search recovers consumer_secret and token_secret. | Aug 19, 2026 |
| CVE-2026-72889(opens NVD record) | Critical | 9.8 | Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the signature method class from the signature_method parameter of the incoming message. signature_method is required on every request, so the algorithm used to check a signature is chosen by whoever sent it, and nothing lets the verifying party pin the method instead. When a message names HMAC-SHA1 or HMAC-SHA256, the key is derived from consumer_secret and token_secret rather than from the key the provider deployed. A provider deployed on RSA-SHA1 holds only the consumer public key, and RFC 5849 does not use consumer_secret for that method, so the required parameter is filled with a placeholder. A client that names HMAC-SHA1 instead has its signature checked against that placeholder, so a guessable one is enough to forge requests for any consumer key and token. | Aug 19, 2026 |
| CVE-2026-58088(opens NVD record) | High | 7.4 | The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the corresponding program headers, then iterated over the map a second time to populate them. A process sharing the address space via rfork(2) can mutate the map between the two passes, causing the second pass to write program headers past the end of the buffer. An unprivileged local user sharing an address space with a process that dumps core can trigger an out-of-bounds write on the kernel heap, potentially leading to privilege escalation. | Aug 19, 2026 |
| CVE-2026-58087(opens NVD record) | High | 7.8 | The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dropped the lock protecting the set, allocated a buffer sized for that count, and reacquired the lock. A sequence-number check was used to verify that the set had not been replaced in the interim, but the sequence number wraps after 0x8000 create/destroy cycles. By rapidly destroying and recreating semaphore sets at the same index, another process can cause the sequence number to wrap, allowing a set with a different number of semaphores to pass validation. The subsequent copy then reads or writes past the end of the allocated buffer. An unprivileged local user can trigger out-of-bounds reads and writes on kernel heap memory, potentially leading to privilege escalation. | Aug 19, 2026 |
| CVE-2026-58086(opens NVD record) | High | 8.1 | As an inadvertent side effect of an unrelated code change, PRIV_KTRACE was always denied to a jailed root user. Tracing configured by a jailed root user was therefore not flagged as privileged. An unprivileged user in a jail that has permission to debug the target process can modify the jailed root user's ktrace(2) flags, or disable tracing outright. A jailed root user therefore cannot reliably trace unprivileged processes. | Aug 19, 2026 |
| CVE-2026-58085(opens NVD record) | High | 7.5 | After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to check whether the MAC verification step succeeded. The driver thus silently accepted packets with an invalid Poly1305 authentication tag. A remote attacker who can send UDP packets to a WireGuard endpoint, and who can guess the bounds of the receiver's replay window, can inject forged or modified transport data packets into the tunnel. A remote attacker who can intercept WireGuard packets bound for a FreeBSD host can modify the ciphertext and authenticated data without detection by the receiver. | Aug 19, 2026 |
| CVE-2026-58084(opens NVD record) | Medium | 5.5 | To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the current time for the timer's clock. For a timer using CLOCK_TAI this can fail when no TAI offset has been configured, but the error return was not checked, so the uninitialized output buffer was copied to userspace. An unprivileged local user can obtain uninitialized kernel stack memory by creating a POSIX timer with CLOCK_TAI and calling timer_settime(2), potentially disclosing sensitive kernel data. | Aug 19, 2026 |
| CVE-2026-58083(opens NVD record) | High | 8.4 | While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be enqueued on the kqueue's active list before the copy was complete. The copy routine did not account for this and could enqueue the new knote a second time, corrupting the active list. In addition, the copy routine did not hold the appropriate locks while reading knote state, allowing further races. An unprivileged local user can trigger a use-after-free in the kernel, potentially leading to privilege escalation. | Aug 19, 2026 |
| CVE-2026-58082(opens NVD record) | Critical | 9.8 | The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate character output. Some ISO-2022 variants can require up to 10 bytes per character, in which case conversions can trigger a stack buffer overflow of up to four bytes. An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be vulnerable to buffer overflows if it uses one of the affected encoding modules. | Aug 19, 2026 |
| CVE-2026-58081(opens NVD record) | Critical | 9.8 | Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before writing converted characters. An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be vulnerable to buffer overflows if it uses one of the affected encoding modules. | Aug 19, 2026 |
| CVE-2026-49425(opens NVD record) | Medium | 5.5 | The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct. It did not first zero the stack struct. An unprivileged user may observe a small amount of uninitialized kernel stack data, which may contain sensitive information. | Aug 19, 2026 |