Search
30,126 CVEs
CVEs (30,126, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 30,126 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9799 | MEDIUM | Patched | 4.6 | 2026-06-25 | A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using … |
| CVE-2026-9787 | HIGH | Patched | 8.8 | 2026-06-25 | Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected … |
| CVE-2026-9786 | HIGH | Patched | 8.8 | 2026-06-25 | Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected inst… |
| CVE-2026-9785 | HIGH | Patched | 8.8 | 2026-06-25 | Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in… |
| CVE-2026-9784 | HIGH | Patched | 8.8 | 2026-06-25 | Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in… |
| CVE-2026-9783 | HIGH | Patched | 8.8 | 2026-06-25 | Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected… |
| CVE-2026-9782 | HIGH | Patched | 8.8 | 2026-06-25 | Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in… |
| CVE-2026-9781 | HIGH | Patched | 8.8 | 2026-06-25 | Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected inst… |
| CVE-2026-9780 | HIGH | Patched | 8.8 | 2026-06-25 | Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected i… |
| CVE-2026-9779 | HIGH | Patched | 7.2 | 2026-06-24 | ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execu… |
| CVE-2026-9778 | HIGH | Patched | 7.2 | 2026-06-24 | ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected insta… |
| CVE-2026-9777 | HIGH | Patched | 7.2 | 2026-06-24 | ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installation… |
| CVE-2026-9776 | HIGH | Patched | 7.5 | 2026-06-24 | ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive inform… |
| CVE-2026-9775 | MEDIUM | Patched | 6.5 | 2026-06-24 | ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installati… |
| CVE-2026-9774 | MEDIUM | Patched | 6.5 | 2026-06-24 | ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected instal… |
| CVE-2026-9773 | HIGH | Patched | 8.8 | 2026-06-24 | Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal… |
| CVE-2026-9772 | HIGH | Patched | 8.8 | 2026-06-24 | Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install… |
| CVE-2026-9771 | HIGH | 8.8 | 2026-08-17 | The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USERSPACE enabled, this handler is the kernel-side trus… | |
| CVE-2026-9770 | MEDIUM | Patched | 5.3 | 2026-07-15 | Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices. An attacker with access to th… |
| CVE-2026-9769 | HIGH | Patched | 7.5 | 2026-08-23 | justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() uncondit… |
| CVE-2026-9767 | MEDIUM | 6.5 | 2026-08-16 | The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and in… | |
| CVE-2026-9765 | HIGH | 7.1 | 2026-07-24 | Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are “Broken” when a user can access resources they are n… | |
| CVE-2026-9762 | HIGH | Patched | 7.8 | 2026-07-17 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control. |
| CVE-2026-9758 | HIGH | 7.3 | 2026-06-10 | Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to be considered trusted | |
| CVE-2026-9756 | MEDIUM | 6.4 | 2026-07-03 | The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute in all versions up to, an… |