Search
3,163 CVEs
CVEs (3,163, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 3,163 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16380 | CRITICAL | Patched | 9.1 | 2026-07-21 | Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16381 | CRITICAL | Patched | 9.1 | 2026-07-21 | Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
| CVE-2026-16370 | CRITICAL | Patched | 9.1 | 2026-07-21 | Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16359 | CRITICAL | Patched | 9.1 | 2026-07-21 | Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and T… |
| CVE-2026-16364 | CRITICAL | Patched | 9.1 | 2026-07-21 | Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-64609 | CRITICAL | Patched | 9.1 | 2026-07-21 | Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying… |
| CVE-2026-62415 | CRITICAL | 9.1 | 2026-07-21 | Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow u… | |
| CVE-2026-44231 | CRITICAL | Patched | 9.1 | 2026-07-20 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and pri… |
| CVE-2026-62414 | CRITICAL | 9.1 | 2026-07-20 | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply access control to fronten… | |
| CVE-2026-46428 | NONE | — | 2026-07-20 | lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's `boring-tls` integration silently disabl… | |
| CVE-2026-13147 | CRITICAL | Patched | 9.1 | 2026-07-20 | The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue … |
| CVE-2026-63992 | CRITICAL | 9.1 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() In some cases, iptunnel_pmtud_c… | |
| CVE-2026-52199 | CRITICAL | 9.1 | 2026-07-17 | An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component | |
| CVE-2026-42168 | CRITICAL | 9.1 | 2026-07-17 | django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. These fields are passed directly to os.system… | |
| CVE-2025-51677 | CRITICAL | 9.1 | 2026-07-17 | An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can lead to unexpected behavior. | |
| CVE-2026-12694 | CRITICAL | Patched | 9.1 | 2026-07-17 | Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterpri… |
| CVE-2024-23564 | CRITICAL | 9.1 | 2026-07-17 | HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to th… | |
| CVE-2026-62241 | CRITICAL | Patched | 9.1 | 2026-07-17 | clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.exam… |
| CVE-2026-16723 | CRITICAL | 9.0 | 2026-07-23 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no Au… | |
| CVE-2026-61223 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). Supported versions that are affected are 8.… | |
| CVE-2026-61204 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). The supported version that is affected … | |
| CVE-2026-61201 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.2.23. … | |
| CVE-2026-61174 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. … | |
| CVE-2026-60424 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.… | |
| CVE-2026-60249 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 an… |