Search
66,771 CVEs
CVEs (66,771, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 66,771 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63795 | CRITICAL | 10.0 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error path When p9_client_walk() is called with clone set… | |
| CVE-2026-16117 | CRITICAL | Patched | 10.0 | 2026-07-18 | Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes path… |
| CVE-2026-54159 | CRITICAL | Patched | 10.0 | 2026-07-17 | PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected search filters from the … |
| CVE-2026-44181 | NONE | Patched | — | 2026-07-16 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions 2.0.0rc2 and ab… |
| CVE-2026-44182 | NONE | Patched | — | 2026-07-16 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions prior to 3.3.0,… |
| CVE-2026-45336 | CRITICAL | 10.0 | 2026-07-16 | HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-… | |
| CVE-2026-52887 | CRITICAL | Patched | 10.0 | 2026-07-15 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-… |
| CVE-2026-46339 | CRITICAL | Patched | 10.0 | 2026-07-15 | 9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated… |
| CVE-2026-50148 | CRITICAL | Patched | 10.0 | 2026-07-15 | Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase… |
| CVE-2026-56699 | CRITICAL | Patched | 10.0 | 2026-07-15 | Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON o… |
| CVE-2026-15409 | CRITICAL | 10.0 | 2026-07-14 | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially ca… | |
| CVE-2026-10577 | NONE | — | 2026-07-14 | A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce proper privilege contr… | |
| CVE-2026-62422 | CRITICAL | Patched | 10.0 | 2026-07-14 | In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leadin… |
| CVE-2026-56451 | CRITICAL | 10.0 | 2026-07-14 | A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT)… | |
| CVE-2026-57811 | CRITICAL | 10.0 | 2026-07-13 | Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusio… | |
| CVE-2026-57719 | CRITICAL | 10.0 | 2026-07-13 | Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/… | |
| CVE-2026-61447 | CRITICAL | Patched | 10.0 | 2026-07-11 | PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import… |
| CVE-2026-54769 | CRITICAL | 10.0 | 2026-07-10 | Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code … | |
| CVE-2026-59726 | CRITICAL | Patched | 10.0 | 2026-07-09 | Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group e… |
| CVE-2026-54782 | CRITICAL | Patched | 10.0 | 2026-07-08 | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does … |
| CVE-2026-57572 | CRITICAL | Patched | 10.0 | 2026-07-06 | Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed int… |
| CVE-2026-54763 | CRITICAL | Patched | 10.0 | 2026-07-06 | Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cas… |
| CVE-2026-48316 | CRITICAL | 10.0 | 2026-07-06 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of t… | |
| CVE-2026-13768 | CRITICAL | 10.0 | 2026-07-03 | Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection in… | |
| CVE-2026-56004 | CRITICAL | 10.0 | 2026-07-02 | A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute… |