IM
IronMonkey Threat Research

CVE Dashboard

Explore and analyze Common Vulnerabilities and Exposures

CVE DATABASE
|
Total CVEs 367,831
|
Page 1 of 36784
|
Showing 10 per page

CVE Listing

367831 results
Loading...
CVE-2026-86098 HIGH 2026-09-04 · Received
ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overf...
CVE-2026-86097 HIGH 2026-09-04 · Received
PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_backup_file() functions that allows attackers to crash the autopilot process. A...
CVE-2026-86096 MEDIUM 2026-09-04 · Received
PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race condition between task spawning and object deletion. Attackers can trigger the cal...
CVE-2026-86095 HIGH 2026-09-04 · Received
Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attacke...
CVE-2026-48019 HIGH 2026-09-04 · Received
Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime han...
CVE-2026-86091 HIGH 2026-09-04 · Received
ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue P...
CVE-2026-86090 HIGH 2026-09-04 · Received
ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly de...
CVE-2026-82684 HIGH 2026-09-04 · Received
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash ...
CVE-2026-77393 HIGH 2026-09-04 · Received
In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8....
CVE-2026-76925 MEDIUM 2026-09-04 · Received
A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. This vulnerability occurs because a privileged `chmo...