Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,173 CVEs

CVEs (3,173, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 401–425 of 3,173 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-59526 CRITICAL 9.3 2026-07-23 Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-8152 NONE &mdash; 2026-07-22 Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack. When Unblu Spark is deployed with com.unblu.id&hellip;
CVE-2026-61207 CRITICAL 9.3 2026-07-21 Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft (component: Manage Requisition Status). The supported version that is affected is&hellip;
CVE-2026-61175 CRITICAL 9.3 2026-07-21 Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. &hellip;
CVE-2026-60631 CRITICAL 9.3 2026-07-21 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.&hellip;
CVE-2026-60632 CRITICAL 9.3 2026-07-21 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.&hellip;
CVE-2026-60248 CRITICAL 9.3 2026-07-21 Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 an&hellip;
CVE-2026-60220 CRITICAL 9.3 2026-07-21 Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 an&hellip;
CVE-2026-65057 CRITICAL 9.3 2026-07-21 Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supply&hellip;
CVE-2026-47708 NONE &mdash; 2026-07-21 MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` API and CLI is directly &hellip;
CVE-2026-64825 CRITICAL Patched 9.3 2026-07-21 Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host file&hellip;
CVE-2026-65048 CRITICAL 9.3 2026-07-21 Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature whe&hellip;
CVE-2026-65049 CRITICAL 9.3 2026-07-21 Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network&hellip;
CVE-2026-39878 CRITICAL Patched 9.3 2026-07-20 Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execu&hellip;
CVE-2026-57309 NONE &mdash; 2026-07-20 A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in HTTP header resulting &hellip;
CVE-2026-64080 CRITICAL 9.3 2026-07-19 In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Snapshot notifier callbacks under lock Both notification handlers currently look up&hellip;
CVE-2026-64034 CRITICAL 9.3 2026-07-19 In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer In mana_hwc_rx_event_handler(), resp-&hellip;
CVE-2026-64018 CRITICAL 9.3 2026-07-19 In the Linux kernel, the following vulnerability has been resolved: net: mana: validate rx_req_idx to prevent out-of-bounds array access In mana_hwc_rx_event_handler(), r&hellip;
CVE-2026-63938 CRITICAL 9.3 2026-07-19 In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Check PSC request indices against the actual size of the buffer When processing Page State C&hellip;
CVE-2026-63939 CRITICAL 9.3 2026-07-19 In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Compute the correct max length of the in-GHCB scratch area When setting the length of the GH&hellip;
CVE-2026-63940 CRITICAL 9.3 2026-07-19 In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Ignore Port I/O requests of length '0' Explicitly ignore Port I/O requests of length '0' (or&hellip;
CVE-2026-15091 CRITICAL 9.3 2026-07-17 IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation.
CVE-2026-9586 NONE &mdash; 2026-07-17 An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> &hellip;
CVE-2026-54496 CRITICAL Patched 9.3 2026-07-17 ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base sc&hellip;
CVE-2026-65760 NONE &mdash; 2026-07-23 Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in us&hellip;