Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

23,162 CVEs

CVEs (23,162, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 26–50 of 23,162 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-63795 CRITICAL 10.0 2026-07-19 In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error path When p9_client_walk() is called with clone set…
CVE-2026-16117 CRITICAL Patched 10.0 2026-07-18 Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes path…
CVE-2026-54159 CRITICAL Patched 10.0 2026-07-17 PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected search filters from the …
CVE-2026-44181 NONE Patched — 2026-07-16 Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions 2.0.0rc2 and ab…
CVE-2026-44182 NONE Patched — 2026-07-16 Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions prior to 3.3.0,…
CVE-2026-45336 CRITICAL 10.0 2026-07-16 HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-…
CVE-2026-52887 CRITICAL Patched 10.0 2026-07-15 NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-…
CVE-2026-46339 CRITICAL Patched 10.0 2026-07-15 9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated…
CVE-2026-50148 CRITICAL Patched 10.0 2026-07-15 Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase…
CVE-2026-56699 CRITICAL Patched 10.0 2026-07-15 Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON o…
CVE-2026-15409 CRITICAL 10.0 2026-07-14 A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially ca…
CVE-2026-10577 NONE — 2026-07-14 A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce proper privilege contr…
CVE-2026-62422 CRITICAL Patched 10.0 2026-07-14 In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leadin…
CVE-2026-56451 CRITICAL 10.0 2026-07-14 A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT)&hellip;
CVE-2026-57811 CRITICAL 10.0 2026-07-13 Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusio&hellip;
CVE-2026-57719 CRITICAL 10.0 2026-07-13 Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/&hellip;
CVE-2026-61447 CRITICAL Patched 10.0 2026-07-11 PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import&hellip;
CVE-2026-54769 CRITICAL 10.0 2026-07-10 Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code &hellip;
CVE-2026-59726 CRITICAL Patched 10.0 2026-07-09 Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group e&hellip;
CVE-2026-54782 CRITICAL Patched 10.0 2026-07-08 CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does &hellip;
CVE-2026-57572 CRITICAL Patched 10.0 2026-07-06 Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed int&hellip;
CVE-2026-54763 CRITICAL Patched 10.0 2026-07-06 Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cas&hellip;
CVE-2026-48316 CRITICAL 10.0 2026-07-06 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of t&hellip;
CVE-2026-13768 CRITICAL 10.0 2026-07-03 Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection in&hellip;
CVE-2026-56004 CRITICAL 10.0 2026-07-02 A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute&hellip;