Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,173 CVEs

CVEs (3,173, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 376–400 of 3,173 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-55518 CRITICAL Patched 9.6 2026-07-17 Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in the U&hellip;
CVE-2026-8986 NONE &mdash; 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP serv&hellip;
CVE-2026-47670 NONE &mdash; 2026-07-23 DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can &hellip;
CVE-2026-63048 NONE &mdash; 2026-07-22 Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file &hellip;
CVE-2026-8987 NONE &mdash; 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated at&hellip;
CVE-2026-61203 CRITICAL 9.4 2026-07-21 Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploita&hellip;
CVE-2026-61186 CRITICAL 9.4 2026-07-21 Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily&hellip;
CVE-2026-47407 NONE &mdash; 2026-07-21 PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources under `/api/v1/workspaces&hellip;
CVE-2026-53595 CRITICAL 9.4 2026-07-20 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` &hellip;
CVE-2026-16337 NONE &mdash; 2026-07-20 Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenti&hellip;
CVE-2026-61425 NONE &mdash; 2026-07-20 Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full &hellip;
CVE-2026-60032 NONE &mdash; 2026-07-20 Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upl&hellip;
CVE-2026-60034 NONE &mdash; 2026-07-20 Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsaniti&hellip;
CVE-2026-16242 CRITICAL 9.4 2026-07-20 A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without toke&hellip;
CVE-2026-64024 CRITICAL 9.4 2026-07-19 In the Linux kernel, the following vulnerability has been resolved: tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction Blamed commit moved the TIME_WAIT-deriv&hellip;
CVE-2026-63830 CRITICAL 9.4 2026-07-19 In the Linux kernel, the following vulnerability has been resolved: net: skmsg: preserve sg.copy across SG transforms The sk_msg sg.copy bitmap is part of the scatterlist&hellip;
CVE-2025-71392 NONE Patched &mdash; 2026-07-18 SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command. An authenticated Syste&hellip;
CVE-2026-12693 CRITICAL Patched 9.4 2026-07-17 Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. &hellip;
CVE-2026-47669 NONE &mdash; 2026-07-23 DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not val&hellip;
CVE-2026-65761 NONE &mdash; 2026-07-23 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated S&hellip;
CVE-2026-61948 CRITICAL 9.3 2026-07-23 Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.
CVE-2026-61949 CRITICAL 9.3 2026-07-23 Unauthenticated SQL Injection in Bookly <= 27.7 versions.
CVE-2026-61950 CRITICAL 9.3 2026-07-23 Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
CVE-2026-59514 CRITICAL 9.3 2026-07-23 Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.
CVE-2026-59525 CRITICAL 9.3 2026-07-23 Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.