Search
23,162 CVEs
CVEs (23,162, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 23,162 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6737 | NONE | Patched | — | 2026-05-08 | An Exposed IOCTL with Insufficient Access Control vulnerability in AsusPTPFilter allows a local user to bypass driver security mechanisms and obtain restricted touchpad inf… |
| CVE-2025-54505 | NONE | — | 2026-04-27 | A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor unit, potentially resulting in lo… | |
| CVE-2026-53910 | NONE | Patched | — | 2026-07-22 | diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in m… |
| CVE-2026-48978 | NONE | Patched | — | 2026-07-17 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validatin… |
| CVE-2026-61448 | NONE | Patched | — | 2026-07-11 | Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8.6.83. When an uploaded file's extension is not… |
| CVE-2026-56813 | NONE | Patched | — | 2026-07-10 | Improper Neutralization of Parameter/Argument Delimiters vulnerability in elixir-plug plug allows an attacker to inject or override HTTP cookie attributes. The Plug.Conn.C… |
| CVE-2026-58225 | NONE | Patched | — | 2026-07-10 | SQL Injection vulnerability in elixir-ecto postgrex allows an attacker who can influence a LISTEN channel name to inject SQL into the reconnect replay query, causing a deni… |
| CVE-2026-55778 | NONE | Patched | — | 2026-07-08 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.11 and 8.6.81, the default fileUpload.fileExten… |
| CVE-2026-59153 | NONE | Patched | — | 2026-07-07 | Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, … |
| CVE-2026-54893 | NONE | Patched | — | 2026-07-06 | URL path injection in the Microsoft Graph adapter of Swoosh. Swoosh.Adapters.MsGraph builds its Microsoft Graph API request URL by interpolating the sender's email address … |
| CVE-2026-54898 | NONE | Patched | — | 2026-07-01 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2,Oj::Parser#parse is vulnerable to a heap use-after-free when … |
| CVE-2026-54896 | NONE | Patched | — | 2026-07-01 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in object mode, Oj.dump is vulnerable to a heap buffer … |
| CVE-2026-54897 | NONE | Patched | — | 2026-07-01 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to 3.17.2, Oj::Doc iterators (each_value, each_child, each_leaf) were vulnerable to… |
| CVE-2026-57940 | NONE | — | 2026-06-26 | HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The function get_feed() in system/admin/admin.php passes user-… | |
| CVE-2026-57533 | NONE | — | 2026-06-25 | Malicious HTML content could be injected into the page pretix shows when redirection to an untrusted page occurs. Since this page has a Content-Security-Policy, this can … | |
| CVE-2026-57534 | NONE | — | 2026-06-25 | Malicious HTML content could be injected into the content of a page in the pretix-pages plugin. | |
| CVE-2026-57535 | NONE | — | 2026-06-25 | Content injected to PDF rendering contexts could, in many places, include HTML content including <img> tags. If the src attribute of these images pointed to an URL, the PD… | |
| CVE-2026-46553 | NONE | Patched | — | 2026-06-23 | NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the upload-by-URL path did not enforce NC_ATTACHMENT_FIELD_SIZE against either the remote fil… |
| CVE-2026-47241 | NONE | Patched | — | 2026-06-22 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a raw string argumen… |
| CVE-2026-40457 | NONE | — | 2026-06-18 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN Management System) before commit 9c5651b in the "dbrecover.php" and "netremap.php" modules where uns… | |
| CVE-2024-24769 | NONE | — | 2026-06-17 | vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, users can reset their MFA token via API routes that send them an email. C… | |
| CVE-2026-53724 | NONE | Patched | — | 2026-06-12 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.79 and 9.9.1-alpha.4, the default file upload … |
| CVE-2026-48485 | NONE | Patched | — | 2026-06-12 | Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the latest release suppresses mentions when creating, unbanning, unwarning, kicking, muting, and unmuting, b… |
| CVE-2026-49738 | NONE | Patched | — | 2026-06-09 | The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requiring a directory separator boundary, causing a path l… |
| CVE-2026-47344 | NONE | — | 2026-06-08 | When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, … |