Search
9,825 CVEs
EOL hidden · Show all products
CVEs (9,825, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 9,825 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-63685 | NONE | — | 2026-07-22 | Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistently require Super User p… | |
| CVE-2026-63684 | NONE | — | 2026-07-22 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administr… | |
| CVE-2026-63683 | NONE | — | 2026-07-22 | Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allo… | |
| CVE-2026-63281 | NONE | — | 2026-07-22 | Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored condition values could also execute HTML/JavaScript in administrator summaries. | |
| CVE-2026-63280 | NONE | — | 2026-07-22 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently e… | |
| CVE-2026-63265 | NONE | — | 2026-07-22 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged Regular Labs AJAX endpo… | |
| CVE-2026-13089 | NONE | — | 2026-07-22 | OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify. When the caller does not pin… | |
| CVE-2025-60835 | NONE | — | 2026-07-22 | An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal. | |
| CVE-2025-50330 | NONE | — | 2026-07-22 | An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe. | |
| CVE-2025-50329 | NONE | — | 2026-07-22 | An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe. | |
| CVE-2025-50327 | NONE | — | 2026-07-22 | An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web prote… | |
| CVE-2025-50325 | NONE | — | 2026-07-22 | BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affec… | |
| CVE-2025-50324 | NONE | — | 2026-07-22 | An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component. | |
| CVE-2025-44090 | NONE | — | 2026-07-22 | An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file. | |
| CVE-2025-44089 | NONE | — | 2026-07-22 | An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file. | |
| CVE-2026-9737 | MEDIUM | 6.5 | 2026-07-22 | During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect tran… | |
| CVE-2026-64829 | HIGH | 7.4 | 2026-07-22 | Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated acce… | |
| CVE-2026-14899 | NONE | Patched | — | 2026-07-22 | The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be … |
| CVE-2026-14881 | HIGH | 7.8 | 2026-07-22 | When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it is possib… | |
| CVE-2026-13078 | HIGH | 7.7 | 2026-07-22 | A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls… | |
| CVE-2026-13077 | HIGH | 7.1 | 2026-07-22 | A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pipeline. The vulnerabili… | |
| CVE-2026-13076 | MEDIUM | 6.5 | 2026-07-22 | An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion operation … | |
| CVE-2026-13075 | MEDIUM | 6.5 | 2026-07-22 | An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusion aggregation stages. T… | |
| CVE-2026-13074 | MEDIUM | 5.3 | 2026-07-22 | An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in e… | |
| CVE-2026-13073 | MEDIUM | 4.3 | 2026-07-22 | An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of servic… |