Search
3,173 CVEs
CVEs (3,173, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 3,173 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55518 | CRITICAL | Patched | 9.6 | 2026-07-17 | Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in the U… |
| CVE-2026-8986 | NONE | — | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP serv… | |
| CVE-2026-47670 | NONE | — | 2026-07-23 | DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can … | |
| CVE-2026-63048 | NONE | — | 2026-07-22 | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file … | |
| CVE-2026-8987 | NONE | — | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated at… | |
| CVE-2026-61203 | CRITICAL | 9.4 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploita… | |
| CVE-2026-61186 | CRITICAL | 9.4 | 2026-07-21 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily… | |
| CVE-2026-47407 | NONE | — | 2026-07-21 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources under `/api/v1/workspaces… | |
| CVE-2026-53595 | CRITICAL | 9.4 | 2026-07-20 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` … | |
| CVE-2026-16337 | NONE | — | 2026-07-20 | Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenti… | |
| CVE-2026-61425 | NONE | — | 2026-07-20 | Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full … | |
| CVE-2026-60032 | NONE | — | 2026-07-20 | Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upl… | |
| CVE-2026-60034 | NONE | — | 2026-07-20 | Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsaniti… | |
| CVE-2026-16242 | CRITICAL | 9.4 | 2026-07-20 | A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without toke… | |
| CVE-2026-64024 | CRITICAL | 9.4 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction Blamed commit moved the TIME_WAIT-deriv… | |
| CVE-2026-63830 | CRITICAL | 9.4 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: net: skmsg: preserve sg.copy across SG transforms The sk_msg sg.copy bitmap is part of the scatterlist… | |
| CVE-2025-71392 | NONE | Patched | — | 2026-07-18 | SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command. An authenticated Syste… |
| CVE-2026-12693 | CRITICAL | Patched | 9.4 | 2026-07-17 | Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. … |
| CVE-2026-47669 | NONE | — | 2026-07-23 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not val… | |
| CVE-2026-65761 | NONE | — | 2026-07-23 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated S… | |
| CVE-2026-61948 | CRITICAL | 9.3 | 2026-07-23 | Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions. | |
| CVE-2026-61949 | CRITICAL | 9.3 | 2026-07-23 | Unauthenticated SQL Injection in Bookly <= 27.7 versions. | |
| CVE-2026-61950 | CRITICAL | 9.3 | 2026-07-23 | Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. | |
| CVE-2026-59514 | CRITICAL | 9.3 | 2026-07-23 | Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions. | |
| CVE-2026-59525 | CRITICAL | 9.3 | 2026-07-23 | Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. |