Search
23,162 CVEs
CVEs (23,162, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 23,162 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-16287 | HIGH | Patched | 7.8 | 2026-07-23 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-u… |
| CVE-2024-58330 | HIGH | 7.5 | 2026-07-23 | A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data. | |
| CVE-2024-58023 | HIGH | 8.4 | 2026-07-23 | Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information. | |
| CVE-2026-9729 | MEDIUM | 6.4 | 2026-07-23 | The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' par… | |
| CVE-2026-9713 | HIGH | 7.5 | 2026-07-23 | The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed… | |
| CVE-2026-9635 | MEDIUM | 6.4 | 2026-07-23 | The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and in… | |
| CVE-2026-59678 | NONE | Patched | — | 2026-07-23 | An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via … |
| CVE-2026-59677 | NONE | — | 2026-07-23 | A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running al… | |
| CVE-2026-12421 | HIGH | 7.2 | 2026-07-23 | The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1 due to insufficient in… | |
| CVE-2026-9577 | MEDIUM | Patched | 4.8 | 2026-07-23 | The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?… |
| CVE-2026-9066 | MEDIUM | Patched | 6.1 | 2026-07-23 | The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of Java… |
| CVE-2026-59676 | NONE | — | 2026-07-23 | A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined … | |
| CVE-2026-14291 | HIGH | Patched | 7.5 | 2026-07-23 | The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an un… |
| CVE-2026-12082 | HIGH | Patched | 7.5 | 2026-07-23 | The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the perma… |
| CVE-2026-7534 | HIGH | 7.2 | 2026-07-23 | The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions … | |
| CVE-2026-7232 | HIGH | 7.2 | 2026-07-23 | The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due to ins… | |
| CVE-2026-64600 | NONE | — | 2026-07-23 | In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both … | |
| CVE-2026-63226 | MEDIUM | 5.8 | 2026-07-23 | Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinatio… | |
| CVE-2026-6390 | MEDIUM | 6.8 | 2026-07-23 | A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted f… | |
| CVE-2026-7120 | MEDIUM | Patched | 5.3 | 2026-07-23 | @fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to an… |
| CVE-2026-15074 | HIGH | Patched | 7.5 | 2026-07-23 | @fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This is a bypass of the earl… |
| CVE-2026-21723 | MEDIUM | 5.3 | 2026-07-23 | The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a… | |
| CVE-2026-16653 | MEDIUM | 5.3 | 2026-07-23 | A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public F… | |
| CVE-2026-16632 | HIGH | 7.3 | 2026-07-23 | A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the library lib/facil/http/parsers/websocket_parser.h of th… | |
| CVE-2026-16631 | MEDIUM | 5.3 | 2026-07-23 | A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Hand… |