Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,217 CVEs

CVEs (30,217, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 251–275 of 30,217 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-48011 LOW 3.7 2026-06-10 Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timin…
CVE-2026-48107 MEDIUM Patched 6.5 2026-06-10 Russh is a Rust SSH client & server library. From version 0.37.0 to before version 0.61.0, in the russh client keyboard-interactive authentication path, a malicious SSH ser…
CVE-2026-48108 MEDIUM Patched 5.3 2026-06-10 Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, russh did not enforce the SSH identification-string rules as deliberately …
CVE-2026-48110 HIGH Patched 7.5 2026-06-10 Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.0, several russh client and server message handlers decoded attacker-controlled SSH …
CVE-2026-50131 HIGH 8.6 2026-06-10 Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SSRF/internal network access in GHSA-p9cg-vqcc-grcx by…
CVE-2026-53634 MEDIUM Patched 4.3 2026-06-10 Sharp is a content management framework built for Laravel as a package. From version 9.0.0 to before version 9.22.3, the create and store endpoints of the Quick Creation Co…
CVE-2026-53736 MEDIUM Patched 4.3 2026-06-10 Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicate_post action handler that lacks nonce verification. Attackers can trick…
CVE-2026-53737 MEDIUM 6.1 2026-06-10 Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can i…
CVE-2026-53738 HIGH 8.1 2026-06-10 Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can …
CVE-2026-53739 MEDIUM 4.3 2026-06-10 Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicate_post_dismiss_notice handler, which verifies no nonce or capability. At…
CVE-2026-53740 MEDIUM 5.4 2026-06-10 Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can schedule a republish copy w…
CVE-2026-53741 MEDIUM 5.4 2026-06-10 Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quote…
CVE-2026-53742 MEDIUM 5.4 2026-06-10 Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access…
CVE-2024-21944 MEDIUM 5.3 2026-06-10 Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, o…
CVE-2026-42305 HIGH Patched 8.8 2026-06-10 Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary file write leading to remo…
CVE-2026-42558 HIGH Patched 7.6 2026-06-10 Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.2, a vulnerability chain consisting o…
CVE-2026-42563 NONE — 2026-06-10 Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, Dulwich's `ProcessMergeDriver` substit…
CVE-2026-42568 MEDIUM 4.3 2026-06-10 Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing s…
CVE-2026-44693 HIGH Patched 8.8 2026-06-10 Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version 6.6.1, Pi-hole FTL contains a race condition vulnerability i…
CVE-2026-46521 MEDIUM Patched 5.5 2026-06-10 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when using LZMA compression in the …
CVE-2026-46557 MEDIUM Patched 6.2 2026-06-10 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-23, due to a missing depth check a stack overflow can …
CVE-2026-46559 MEDIUM Patched 4.0 2026-06-10 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an incorrect check in the JP2 will …
CVE-2026-46645 MEDIUM Patched 4.3 2026-06-10 SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to version 0.25.1, the ajax_lookup endpoint in application.py bypasses the is_accessible() access contro…
CVE-2026-46692 MEDIUM Patched 4.1 2026-06-10 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a ma…
CVE-2026-46693 MEDIUM Patched 4.1 2026-06-10 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a ma…