NIST

CVE intelligence

Cached from NVD. 2026-09-19 PT. Recent.

CVETitleVendorPublishedCVSSKEV listed
CVE-2026-87886Acronis Backup Incorrect Default Permissions VulnerabilityAcronis2026-09-172026-09-16
CVE-2026-76460Cisco Identity Services Engine Incorrect Use of Privileged APIs VulnerabilityCisco2026-09-162026-09-16
CVE-2026-58704Google Pixel Improper Authorization VulnerabilityGoogle2026-09-152026-09-16
CVE-2026-76461Cisco Secure Email Gateway SQL Injection VulnerabilityCisco2026-09-142026-09-14
CVE-2026-85706GitLab Community Edition and Enterprise Edition Path Traversal VulnerabilityGitlab2026-09-122026-09-11
CVE-2026-87491Google Chromium V8 Out of Bounds Write VulnerabilityGoogle2026-09-092026-09-09
CVE-2026-85880Microsoft Windows Heap-Based Buffer Overflow VulnerabilityMicrosoft2026-09-082026-09-08
CVE-2026-84869ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization VulnerabilityConnectwise2026-09-082026-09-11
CVE-2026-81963Microsoft Windows Link Following VulnerabilityMicrosoft2026-09-082026-09-08
CVE-2026-75650Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine VulnerabilityAdobe2026-09-072026-09-08
CVE-2026-86257wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject s2026-09-06
CVE-2026-86256wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). Af2026-09-06
CVE-2026-86255wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbi2026-09-06
CVE-2026-86254wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym2026-09-06
CVE-2026-86253h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments, event.url.pathname2026-09-06
CVE-2026-86252h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject a2026-09-06
CVE-2026-86251h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A double-decoding flaw allows a request path co2026-09-06
CVE-2026-86250h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteCh2026-09-06
CVE-2026-86242Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins whe2026-09-06
CVE-2026-86218N-able N-central Static Code Injection VulnerabilityN-able2026-09-062026-09-08
CVE-2026-86214A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This 2026-09-06
CVE-2026-86213A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/universi2026-09-06
CVE-2026-86212A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation le2026-09-06
CVE-2026-86211A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the compone2026-09-06
CVE-2026-86210A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unk2026-09-06
CVE-2026-86209A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_2026-09-06
CVE-2026-86208A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /d2026-09-06
CVE-2026-86205h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative2026-09-06
CVE-2026-86183A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/d2026-09-06
CVE-2026-86182A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/2026-09-06
CVE-2026-86181A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /use2026-09-06
CVE-2026-86180A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionalit2026-09-06
CVE-2026-86179A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.2026-09-06
CVE-2026-86172A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Perfor2026-09-06
CVE-2026-86171A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.2026-09-06
CVE-2026-86170A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php2026-09-06
CVE-2026-86168A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file 2026-09-06
CVE-2026-86167A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the2026-09-06
CVE-2026-86166A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect2026-09-06
CVE-2026-86165A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Perfo2026-09-06

1–40 of 210Next