Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,163 CVEs

CVEs (3,163, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 426–450 of 3,163 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-50185 NONE Patched — 2026-07-17 RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as branches by the compile…
CVE-2026-53712 NONE Patched — 2026-07-17 SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) authentication mechanisms. Pri…
CVE-2026-48487 NONE Patched — 2026-07-17 Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string and _read_string in src/zeroconf/_protocol/incoming.p…
CVE-2026-45309 NONE Patched — 2026-07-17 AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.0, …
CVE-2026-9586 NONE &mdash; 2026-07-17 An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> &hellip;
CVE-2026-9587 NONE &mdash; 2026-07-17 An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through &hellip;
CVE-2026-9588 NONE &mdash; 2026-07-17 A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_&hellip;
CVE-2026-9585 NONE &mdash; 2026-07-17 An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly saniti&hellip;
CVE-2026-58148 NONE &mdash; 2026-07-17 Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to an unauthenticated sto&hellip;
CVE-2026-15783 NONE Patched &mdash; 2026-07-17 A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata fro&hellip;
CVE-2026-12715 NONE &mdash; 2026-07-17 Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code&hellip;
CVE-2026-14871 NONE &mdash; 2026-07-17 osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem.
CVE-2026-15007 NONE Patched &mdash; 2026-07-17 A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository releas&hellip;
CVE-2026-15343 NONE Patched &mdash; 2026-07-17 A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write f&hellip;
CVE-2026-9592 NONE &mdash; 2026-07-17 SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is &hellip;
CVE-2026-59695 NONE Patched &mdash; 2026-07-17 Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by naming an arb&hellip;
CVE-2026-59252 NONE Patched &mdash; 2026-07-17 Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet, resulting in denial of service for &hellip;
CVE-2026-59694 NONE Patched &mdash; 2026-07-17 Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per payment by a large multipl&hellip;
CVE-2026-22104 NONE &mdash; 2026-07-17 Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of a&hellip;
CVE-2026-62764 NONE Patched &mdash; 2026-07-17 Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user without system permissions may issue a remote comma&hellip;
CVE-2026-15380 NONE &mdash; 2026-07-17 A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3)
CVE-2026-15379 NONE &mdash; 2026-07-17 The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the SYSTEM account, bypass&hellip;
CVE-2019-25764 NONE &mdash; 2026-07-17 **UNSUPPORTED WHEN ASSIGNED**  Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invok&hellip;
CVE-2026-62238 NONE Patched &mdash; 2026-07-17 OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint that constructs PostgreSQL queries by concatenating &hellip;
CVE-2026-42933 CRITICAL 10.0 2026-07-23 Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypa&hellip;