Search
66,781 CVEs
CVEs (66,781, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 66,781 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50185 | NONE | Patched | — | 2026-07-17 | RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as branches by the compile… |
| CVE-2026-53712 | NONE | Patched | — | 2026-07-17 | SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) authentication mechanisms. Pri… |
| CVE-2026-48487 | NONE | Patched | — | 2026-07-17 | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string and _read_string in src/zeroconf/_protocol/incoming.p… |
| CVE-2026-45309 | NONE | Patched | — | 2026-07-17 | AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.0, … |
| CVE-2026-9586 | NONE | — | 2026-07-17 | An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> … | |
| CVE-2026-9587 | NONE | — | 2026-07-17 | An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through … | |
| CVE-2026-9588 | NONE | — | 2026-07-17 | A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_… | |
| CVE-2026-9585 | NONE | — | 2026-07-17 | An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly saniti… | |
| CVE-2026-58148 | NONE | — | 2026-07-17 | Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to an unauthenticated sto… | |
| CVE-2026-15783 | NONE | Patched | — | 2026-07-17 | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata fro… |
| CVE-2026-12715 | NONE | — | 2026-07-17 | Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code… | |
| CVE-2026-14871 | NONE | — | 2026-07-17 | osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem. | |
| CVE-2026-15007 | NONE | Patched | — | 2026-07-17 | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository releas… |
| CVE-2026-15343 | NONE | Patched | — | 2026-07-17 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write f… |
| CVE-2026-9592 | NONE | — | 2026-07-17 | SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is … | |
| CVE-2026-59695 | NONE | Patched | — | 2026-07-17 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by naming an arb… |
| CVE-2026-59252 | NONE | Patched | — | 2026-07-17 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet, resulting in denial of service for … |
| CVE-2026-59694 | NONE | Patched | — | 2026-07-17 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per payment by a large multipl… |
| CVE-2026-22104 | NONE | — | 2026-07-17 | Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of a… | |
| CVE-2026-62764 | NONE | Patched | — | 2026-07-17 | Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user without system permissions may issue a remote comma… |
| CVE-2026-15380 | NONE | — | 2026-07-17 | A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3) | |
| CVE-2026-15379 | NONE | — | 2026-07-17 | The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the SYSTEM account, bypass… | |
| CVE-2019-25764 | NONE | — | 2026-07-17 | **UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invok… | |
| CVE-2026-62238 | NONE | Patched | — | 2026-07-17 | OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint that constructs PostgreSQL queries by concatenating … |
| CVE-2026-44181 | NONE | Patched | — | 2026-07-16 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions 2.0.0rc2 and ab… |