Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

78,575 CVEs

CVEs (78,575, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 351–375 of 78,575 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9565 MEDIUM 6.3 2026-05-26 A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file apps/runtime/src-tauri/src/agent/tools/bash.rs of the…
CVE-2026-9564 LOW 2.4 2026-05-26 A vulnerability was found in SourceCodester/oretnom23 Hospitals Patient Records Management System 1.0. The impacted element is an unknown function of the file /admin/?page=…
CVE-2026-9563 HIGH 7.5 2026-07-02 In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number of characters consumed while pars…
CVE-2026-9562 HIGH 7.3 2026-05-26 A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The affected element is an unknown function of the com…
CVE-2026-9561 HIGH Patched 8.2 2026-07-14 Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The or…
CVE-2026-9560 HIGH Patched 7.8 2026-05-26 Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via loca…
CVE-2026-9559 CRITICAL 9.9 2026-05-29 A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic…
CVE-2026-9558 CRITICAL 9.9 2026-05-29 A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function res…
CVE-2026-9557 MEDIUM 6.4 2026-05-29 A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigg…
CVE-2026-9552 HIGH 7.3 2026-05-26 A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown code of the component Search API Endpoint. The…
CVE-2026-9551 HIGH 7.3 2026-05-26 A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of the file ParkingRecord/ExportParkingRecords o…
CVE-2026-9550 HIGH 7.3 2026-05-26 A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is some unknown functionalit…
CVE-2026-9549 MEDIUM 4.8 2026-06-08 Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can c&hellip;
CVE-2026-9548 MEDIUM Patched 6.5 2026-08-28 An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows re&hellip;
CVE-2026-9547 HIGH Patched 7.4 2026-07-03 When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted serve&hellip;
CVE-2026-9546 HIGH Patched 7.5 2026-07-03 A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation states that passing NULL to `CURLOPT_REFERER` &hellip;
CVE-2026-9545 HIGH Patched 7.5 2026-07-03 In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the atta&hellip;
CVE-2026-9544 HIGH 7.3 2026-05-26 A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by this vulnerability is an unknown functionality of the f&hellip;
CVE-2026-9543 CRITICAL 9.8 2026-05-26 A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Managem&hellip;
CVE-2026-9542 MEDIUM 6.3 2026-05-26 A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executing a manipulat&hellip;
CVE-2026-9541 MEDIUM Patched 5.3 2026-05-26 A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Perform&hellip;
CVE-2026-9540 MEDIUM 5.3 2026-05-26 A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation le&hellip;
CVE-2026-9539 MEDIUM 6.5 2026-06-24 An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 on hypervisor host environmen&hellip;
CVE-2026-9538 HIGH Patched 7.5 2026-05-26 Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $han&hellip;
CVE-2026-9537 MEDIUM Patched 5.3 2026-07-17 Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature to the recom&hellip;