Search
66,771 CVEs
CVEs (66,771, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 66,771 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54419 | CRITICAL | Patched | 10.0 | 2025-07-28 | A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from the (unsigned) original response document. This is di… |
| CVE-2025-5120 | CRITICAL | Patched | 10.0 | 2025-07-27 | A sandbox escape vulnerability was identified in huggingface/smolagents version 1.14.0, allowing attackers to bypass the restricted execution environment and achieve remote… |
| CVE-2014-125115 | NONE | — | 2025-07-25 | An unauthenticated SQL injection vulnerability exists in Pandora FMS version 5.0 SP2 and earlier. The mobile/index.php endpoint fails to properly sanitize user input in the… | |
| CVE-2025-5243 | CRITICAL | Patched | 10.0 | 2025-07-24 | Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SMG Software In… |
| CVE-2025-41240 | CRITICAL | 10.0 | 2025-07-24 | Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document root. In affected versio… | |
| CVE-2026-63732 | CRITICAL | Patched | 9.9 | 2026-07-23 | 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL… |
| CVE-2024-58354 | CRITICAL | 9.9 | 2026-07-23 | cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_req… | |
| CVE-2026-47724 | CRITICAL | 9.9 | 2026-07-23 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trusts the bearer token alon… | |
| CVE-2026-47752 | CRITICAL | 9.9 | 2026-07-23 | Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notifica… | |
| CVE-2026-59543 | CRITICAL | 9.9 | 2026-07-23 | Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions. | |
| CVE-2026-60369 | CRITICAL | 9.9 | 2026-07-22 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a… | |
| CVE-2026-61242 | CRITICAL | 9.9 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1.… | |
| CVE-2026-61237 | CRITICAL | 9.9 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9… | |
| CVE-2026-61239 | CRITICAL | 9.9 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is … | |
| CVE-2026-61209 | CRITICAL | 9.9 | 2026-07-21 | Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery). The supported version that is affected is 9.2. Ea… | |
| CVE-2026-61211 | CRITICAL | 9.9 | 2026-07-21 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31 and 23.4.0-23.26.2. Easily exploitable vulnerability a… | |
| CVE-2026-61146 | CRITICAL | 9.9 | 2026-07-21 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported … | |
| CVE-2026-61076 | CRITICAL | 9.9 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle PeopleSoft (component: Job Opening). The supported version that is affected is… | |
| CVE-2026-61072 | CRITICAL | 9.9 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office Brazil product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is … | |
| CVE-2026-61041 | CRITICAL | 9.9 | 2026-07-21 | Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security). Supported versions that are affected are 12.2.3-12.2.1… | |
| CVE-2026-60719 | CRITICAL | 9.9 | 2026-07-21 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.0… | |
| CVE-2026-60711 | CRITICAL | 9.9 | 2026-07-21 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easi… | |
| CVE-2026-60663 | CRITICAL | 9.9 | 2026-07-21 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 … | |
| CVE-2026-60627 | CRITICAL | 9.9 | 2026-07-21 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The supported version that is affected is 9.2.26.3. E… | |
| CVE-2026-60568 | CRITICAL | 9.9 | 2026-07-21 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.… |