Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,126 CVEs

CVEs (30,126, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 26–50 of 30,126 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9799 MEDIUM Patched 4.6 2026-06-25 A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using …
CVE-2026-9787 HIGH Patched 8.8 2026-06-25 Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected …
CVE-2026-9786 HIGH Patched 8.8 2026-06-25 Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected inst…
CVE-2026-9785 HIGH Patched 8.8 2026-06-25 Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in…
CVE-2026-9784 HIGH Patched 8.8 2026-06-25 Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in…
CVE-2026-9783 HIGH Patched 8.8 2026-06-25 Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected…
CVE-2026-9782 HIGH Patched 8.8 2026-06-25 Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in…
CVE-2026-9781 HIGH Patched 8.8 2026-06-25 Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected inst…
CVE-2026-9780 HIGH Patched 8.8 2026-06-25 Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected i…
CVE-2026-9779 HIGH Patched 7.2 2026-06-24 ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execu…
CVE-2026-9778 HIGH Patched 7.2 2026-06-24 ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected insta…
CVE-2026-9777 HIGH Patched 7.2 2026-06-24 ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installation…
CVE-2026-9776 HIGH Patched 7.5 2026-06-24 ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive inform…
CVE-2026-9775 MEDIUM Patched 6.5 2026-06-24 ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installati…
CVE-2026-9774 MEDIUM Patched 6.5 2026-06-24 ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected instal…
CVE-2026-9773 HIGH Patched 8.8 2026-06-24 Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal…
CVE-2026-9772 HIGH Patched 8.8 2026-06-24 Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install…
CVE-2026-9771 HIGH 8.8 2026-08-17 The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USERSPACE enabled, this handler is the kernel-side trus…
CVE-2026-9770 MEDIUM Patched 5.3 2026-07-15 Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices.  An attacker with access to th…
CVE-2026-9769 HIGH Patched 7.5 2026-08-23 justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() uncondit…
CVE-2026-9767 MEDIUM 6.5 2026-08-16 The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and in…
CVE-2026-9765 HIGH 7.1 2026-07-24 Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are “Broken” when a user can access resources they are n…
CVE-2026-9762 HIGH Patched 7.8 2026-07-17 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.
CVE-2026-9758 HIGH 7.3 2026-06-10 Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to be considered trusted
CVE-2026-9756 MEDIUM 6.4 2026-07-03 The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute in all versions up to, an…