Search
3,173 CVEs
CVEs (3,173, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 3,173 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59526 | CRITICAL | 9.3 | 2026-07-23 | Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | |
| CVE-2026-8152 | NONE | — | 2026-07-22 | Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack. When Unblu Spark is deployed with com.unblu.id… | |
| CVE-2026-61207 | CRITICAL | 9.3 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft (component: Manage Requisition Status). The supported version that is affected is… | |
| CVE-2026-61175 | CRITICAL | 9.3 | 2026-07-21 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. … | |
| CVE-2026-60631 | CRITICAL | 9.3 | 2026-07-21 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.… | |
| CVE-2026-60632 | CRITICAL | 9.3 | 2026-07-21 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.… | |
| CVE-2026-60248 | CRITICAL | 9.3 | 2026-07-21 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 an… | |
| CVE-2026-60220 | CRITICAL | 9.3 | 2026-07-21 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 an… | |
| CVE-2026-65057 | CRITICAL | 9.3 | 2026-07-21 | Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supply… | |
| CVE-2026-47708 | NONE | — | 2026-07-21 | MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` API and CLI is directly … | |
| CVE-2026-64825 | CRITICAL | Patched | 9.3 | 2026-07-21 | Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host file… |
| CVE-2026-65048 | CRITICAL | 9.3 | 2026-07-21 | Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature whe… | |
| CVE-2026-65049 | CRITICAL | 9.3 | 2026-07-21 | Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network… | |
| CVE-2026-39878 | CRITICAL | Patched | 9.3 | 2026-07-20 | Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execu… |
| CVE-2026-57309 | NONE | — | 2026-07-20 | A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in HTTP header resulting … | |
| CVE-2026-64080 | CRITICAL | 9.3 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Snapshot notifier callbacks under lock Both notification handlers currently look up… | |
| CVE-2026-64034 | CRITICAL | 9.3 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer In mana_hwc_rx_event_handler(), resp-… | |
| CVE-2026-64018 | CRITICAL | 9.3 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: net: mana: validate rx_req_idx to prevent out-of-bounds array access In mana_hwc_rx_event_handler(), r… | |
| CVE-2026-63938 | CRITICAL | 9.3 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Check PSC request indices against the actual size of the buffer When processing Page State C… | |
| CVE-2026-63939 | CRITICAL | 9.3 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Compute the correct max length of the in-GHCB scratch area When setting the length of the GH… | |
| CVE-2026-63940 | CRITICAL | 9.3 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Ignore Port I/O requests of length '0' Explicitly ignore Port I/O requests of length '0' (or… | |
| CVE-2026-15091 | CRITICAL | 9.3 | 2026-07-17 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation. | |
| CVE-2026-9586 | NONE | — | 2026-07-17 | An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> … | |
| CVE-2026-54496 | CRITICAL | Patched | 9.3 | 2026-07-17 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base sc… |
| CVE-2026-65760 | NONE | — | 2026-07-23 | Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in us… |