CVE search

369,933 results
CVE-2026-58029MEDIUMFull Account Takeover from BotPasswords and OAuth via action=changeauthenticationdataEPSS 0.4%CVE-2026-58028NONEPretty-printed API output combined with centralauthtoken allows XSS with certain gadgetsEPSS 0.3%CVE-2026-24270CRITICALNVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability EPSS 0.8%CVE-2026-57517CRITICALControl Web Panel < 0.9.8.1225 Blind SQL Injection via userRes ParameterEPSS 0.6%CVE-2026-24266MEDIUMNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit oEPSS 0.7%CVE-2026-24264HIGHNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highly compressed data. AEPSS 0.8%CVE-2026-58026NONE$wgNonincludableNamespaces can be bypassed by embedding redirect in other namespacesEPSS 0.4%CVE-2026-8857NONEFull RCE using EasyTimeline ExtensionEPSS 0.3%CVE-2026-58038NONEStored XSS through javascript URLs in SVGs generated by EasyTimelineEPSS 0.2%CVE-2026-58027MEDIUMQueryAbuseFilter API can be used to see the hit count of private filters, which is hidden in the UIEPSS 0.4%CVE-2026-24251HIGHNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resourcEPSS 0.2%CVE-2026-24250HIGHNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs. A successful EPSS 0.2%CVE-2026-58030MEDIUMSyntaxHighlight stored XSS via unsanitized 'linelinks' attributeEPSS 0.3%CVE-2026-24249HIGHNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful explEPSS 0.2%CVE-2026-24248HIGHNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exEPSS 0.2%CVE-2026-24247HIGHNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful explEPSS 0.2%CVE-2026-58032MEDIUMmw.Api.getErrorMessage() may return injected HTML if used without errorformat=htmlEPSS 0.3%CVE-2026-24246HIGHNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resourcEPSS 0.2%CVE-2026-24245HIGHNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful explEPSS 0.2%CVE-2026-58033MEDIUM"Total number of distinct authors" statistic at action=info does not exclude revisions where the author name was deletedEPSS 0.4%