Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

9,831 CVEs

CVEs (9,831, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 401–425 of 9,831 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-63685 NONE — 2026-07-22 Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistently require Super User p…
CVE-2026-63684 NONE — 2026-07-22 Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administr…
CVE-2026-63683 NONE — 2026-07-22 Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allo…
CVE-2026-63281 NONE — 2026-07-22 Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored condition values could also execute HTML/JavaScript in administrator summaries.
CVE-2026-63280 NONE — 2026-07-22 Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently e…
CVE-2026-63265 NONE — 2026-07-22 Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged Regular Labs AJAX endpo…
CVE-2026-13089 NONE — 2026-07-22 OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify. When the caller does not pin…
CVE-2025-60835 NONE — 2026-07-22 An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
CVE-2025-50330 NONE — 2026-07-22 An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.
CVE-2025-50329 NONE — 2026-07-22 An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.
CVE-2025-50327 NONE — 2026-07-22 An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web prote…
CVE-2025-50325 NONE — 2026-07-22 BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affec…
CVE-2025-50324 NONE — 2026-07-22 An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.
CVE-2025-44090 NONE — 2026-07-22 An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
CVE-2025-44089 NONE — 2026-07-22 An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
CVE-2026-9737 MEDIUM 6.5 2026-07-22 During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect tran…
CVE-2026-64829 HIGH 7.4 2026-07-22 Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated acce…
CVE-2026-14899 NONE Patched — 2026-07-22 The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be …
CVE-2026-14881 HIGH 7.8 2026-07-22 When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it is possib…
CVE-2026-13078 HIGH 7.7 2026-07-22 A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls…
CVE-2026-13077 HIGH 7.1 2026-07-22 A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pipeline. The vulnerabili…
CVE-2026-13076 MEDIUM 6.5 2026-07-22 An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion operation …
CVE-2026-13075 MEDIUM 6.5 2026-07-22 An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusion aggregation stages. T…
CVE-2026-13074 MEDIUM 5.3 2026-07-22 An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in e…
CVE-2026-13073 MEDIUM 4.3 2026-07-22 An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of servic…