Search
9,831 CVEs
CVEs (9,831, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 9,831 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-62683 | LOW | Patched | 3.1 | 2026-07-15 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser can … |
| CVE-2026-21840 | LOW | 3.1 | 2026-07-14 | HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, through careful system control and response time monitoring, to perform s… | |
| CVE-2026-15058 | LOW | Patched | 3.1 | 2026-07-14 | Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages vi… |
| CVE-2026-52841 | LOW | 3.1 | 2026-07-14 | Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `p… | |
| CVE-2025-62826 | LOW | Patched | 3.1 | 2026-07-14 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, Fort… |
| CVE-2026-15690 | LOW | 3.1 | 2026-07-14 | A vulnerability was identified in open62541 up to 1.5.5. Affected by this issue is the function responseReadNamespacesArray of the file src/client/ua_client_connect.c of th… | |
| CVE-2026-12482 | LOW | 3.1 | 2026-07-14 | A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` validation in `keras/src/uti… | |
| CVE-2026-15605 | LOW | 3.1 | 2026-07-13 | A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the com… | |
| CVE-2026-61874 | LOW | Patched | 3.1 | 2026-07-12 | filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, allowing authenticated users to leave stale public shar… |
| CVE-2026-55807 | LOW | Patched | 3.1 | 2026-07-10 | Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, f… |
| CVE-2026-13232 | LOW | 3.1 | 2026-07-10 | Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing. This issue affects Advanced Content Feedback (aka a… | |
| CVE-2026-59180 | LOW | Patched | 3.1 | 2026-07-10 | Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. Prior to 1.11.0, Apprise HTTP-b… |
| CVE-2026-59226 | LOW | Patched | 3.1 | 2026-07-09 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_automation rehydrated automation owners without rech… |
| CVE-2026-59715 | LOW | Patched | 3.1 | 2026-07-09 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.16 before 0.10.0, the Socket.IO server is configured with always_connect=True… |
| CVE-2026-59215 | LOW | Patched | 3.1 | 2026-07-09 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread parent and reply handling did not bind parent_id to th… |
| CVE-2026-14966 | LOW | 3.1 | 2026-07-08 | BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect symlinks whose listing carries a DOS-… | |
| CVE-2026-14967 | LOW | 3.1 | 2026-07-08 | BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, s… | |
| CVE-2026-28378 | LOW | Patched | 3.1 | 2026-07-07 | The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a differe… |
| CVE-2026-48588 | LOW | Patched | 3.1 | 2026-07-07 | An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when… |
| CVE-2026-42172 | LOW | Patched | 3.1 | 2026-07-07 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Sanctum API tokens did not expire, allowing a l… |
| CVE-2026-42145 | LOW | Patched | 3.1 | 2026-07-07 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the file upload endpoint (app/Http/Controllers/… |
| CVE-2026-14742 | LOW | 3.1 | 2026-07-05 | A vulnerability was determined in langchain-ai langgraph up to 1.2.4. The affected element is the function _freeze of the file libs/langgraph/langgraph/_internal/_cache.py … | |
| CVE-2026-14630 | LOW | 3.1 | 2026-07-04 | A vulnerability has been found in ForceInjection AI-fundermentals 2.0/3.0. Affected by this vulnerability is the function get_conversation_history of the file 08_agentic_sy… | |
| CVE-2026-14621 | LOW | 3.1 | 2026-07-04 | A vulnerability has been found in FederatedAI FATE up to 2.2.0. This affects the function QueuePushReqStreamObserver.initEggroll of the file java/osx/osx-broker/src/main/ja… | |
| CVE-2026-14617 | LOW | 3.1 | 2026-07-03 | A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function GatewayStreamConsumer._filter_and_accumulate of the file g… |