Search
23,162 CVEs
CVEs (23,162, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 23,162 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44182 | NONE | Patched | — | 2026-07-16 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions prior to 3.3.0,… |
| CVE-2026-11740 | NONE | — | 2026-07-16 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-14253 | NONE | — | 2026-07-16 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-15997 | NONE | Patched | — | 2026-07-16 | Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffers. This vulnerability is associated with program f… |
| CVE-2026-44177 | NONE | Patched | — | 2026-07-16 | Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correctly validate the provided user ID, resulting in a pat… |
| CVE-2026-45334 | NONE | Patched | — | 2026-07-16 | Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the content-locking feature returned lock information without checking the requesti… |
| CVE-2026-45368 | NONE | Patched | — | 2026-07-16 | Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for the KirbyTags and image blocks components did not fi… |
| CVE-2026-44174 | NONE | Patched | — | 2026-07-16 | Kirby is an open-source content management system. Prior to 4.9.1 and 5.4.1, Kirby did not validate the model attributes that were used in its collection queries, allowing … |
| CVE-2026-44175 | NONE | Patched | — | 2026-07-16 | Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, Kirby did not securely sanitize the contents of the list field on save, leaving it … |
| CVE-2026-44176 | NONE | Patched | — | 2026-07-16 | Kirby is an open-source content management system. Versions prior to 4.9.1 and 5.4.1 do not check the `pages.access` permission during page draft rendering. Permissions ar… |
| CVE-2026-62963 | NONE | Patched | — | 2026-07-16 | Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidirectional WebSocket transport with uni_websocket.compression enabled enfor… |
| CVE-2026-54728 | NONE | Patched | — | 2026-07-16 | bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1.6.12 and BunkerWeb PRO 0.57, authenticated Host header handling in the … |
| CVE-2026-55629 | NONE | Patched | — | 2026-07-16 | Whistle is an HTTP, HTTP2, HTTPS, and WebSocket debugging proxy. Prior to 2.10.3, lib/service/service.js handles GET /cgi-bin/temp/get by reading req.query.filename, joinin… |
| CVE-2026-15422 | NONE | — | 2026-07-16 | The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chunk. Since this lookup r… | |
| CVE-2026-15449 | NONE | — | 2026-07-16 | A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link pseudo-driver (dld) affects handling of the DLDIOC_GETMACPROP and DLDIOC_SETMACPROP ioctls on /dev/dld… | |
| CVE-2026-44981 | NONE | Patched | — | 2026-07-16 | CrowdSec offers crowdsourced protection against malicious IPs. From 1.7.0 until 1.7.8, the LAPI router used gin-contrib/gzip with DefaultDecompressHandle globally in pkg/ap… |
| CVE-2026-53535 | NONE | Patched | — | 2026-07-16 | Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-configured Git repository into a temporary directory on … |
| CVE-2026-53536 | NONE | Patched | — | 2026-07-16 | Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endpoint verified the supplied JWT against the shared si… |
| CVE-2026-54526 | NONE | Patched | — | 2026-07-16 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 3.7.15 and 4.0.6, the allow-list fix for CVE-2026-… |
| CVE-2026-46515 | NONE | Patched | — | 2026-07-16 | Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pinsets, fm_show_context, … |
| CVE-2026-46686 | NONE | — | 2026-07-16 | Emlog is an open source website building system. In 2.6.13 and earlier, the admin backend user search module's keyword parameter from admin/user.php is processed with addsl… | |
| CVE-2026-46687 | NONE | — | 2026-07-16 | Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template parameter from api_controller.php … | |
| CVE-2026-47751 | NONE | Patched | — | 2026-07-16 | Claude Code Action is a general-purpose GitHub action that runs Claude Code on GitHub pull requests and issues. Prior to 1.0.74, because the action checked out attacker-con… |
| CVE-2026-55406 | NONE | Patched | — | 2026-07-16 | Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.7.0, a soundness bug in the OwnedView<V> type allowed safe Rust … |
| CVE-2026-55407 | NONE | Patched | — | 2026-07-16 | Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.8.0, the decode_unknown_field function in buffa's protobuf decod… |