Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

23,162 CVEs

CVEs (23,162, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 476–500 of 23,162 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-14371 NONE — 2026-07-16 The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establi…
CVE-2026-59864 NONE Patched — 2026-07-16 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled stat…
CVE-2026-59865 NONE Patched &mdash; 2026-07-16 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus depen&hellip;
CVE-2026-59866 NONE Patched &mdash; 2026-07-16 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or pa&hellip;
CVE-2026-54733 NONE Patched &mdash; 2026-07-16 The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Micr&hellip;
CVE-2026-53597 NONE Patched &mdash; 2026-07-16 Prompty is a markdown file format (.prompty) for LLM prompts. From 2.0.0-alpha.1 until 2.0.0-beta.3, the @prompty/core TypeScript loader in runtime/typescript/packages/core&hellip;
CVE-2026-12379 NONE &mdash; 2026-07-16 An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation of the Axivion Dashboard. The login flow did not properly restrict the post-&hellip;
CVE-2026-59859 NONE Patched &mdash; 2026-07-16 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-&hellip;
CVE-2026-59860 NONE Patched &mdash; 2026-07-16 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.3, Kiota is affected by a code-generation injection vulnerability in the C# XML documentation-comment si&hellip;
CVE-2026-59863 NONE Patched &mdash; 2026-07-16 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota honored a poisoned .kiota/workspace.json workspace configuration without validating per-client &hellip;
CVE-2026-59237 NONE Patched &mdash; 2026-07-16 Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Prospero Flow CRM before 5.5.3 allows a remote, authent&hellip;
CVE-2026-14254 NONE &mdash; 2026-07-16 A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed through concurrent authentication requests. Paralle&hellip;
CVE-2025-71377 NONE Patched &mdash; 2026-07-16 stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another message, the database query &hellip;
CVE-2025-71388 NONE Patched &mdash; 2026-07-16 stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission on a channel to fetch that channel's webhooks, inclu&hellip;
CVE-2026-59249 NONE Patched &mdash; 2026-07-16 Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermed&hellip;
CVE-2026-58078 NONE &mdash; 2026-07-16 Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an unauthen&hellip;
CVE-2026-6423 NONE &mdash; 2026-07-16 A local privilege escalation vulnerability in ESET Inspect Connector.  The vulnerability was caused by improper authentication in an IPC channel.
CVE-2026-6424 NONE &mdash; 2026-07-16 Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the system
CVE-2026-15925 NONE &mdash; 2026-07-16 Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate&hellip;
CVE-2026-63175 NONE &mdash; 2026-07-15 PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than instance-level variables. Consequently, multiple Captu&hellip;
CVE-2026-55445 NONE Patched &mdash; 2026-07-15 Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the init guard middleware in back/loaders/express.ts ch&hellip;
CVE-2026-55576 NONE &mdash; 2026-07-15 MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled g&hellip;
CVE-2026-53446 NONE Patched &mdash; 2026-07-15 Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan webhook integration URLs in models/integrations.js are stored from user input and later fetched by serve&hellip;
CVE-2026-52893 NONE Patched &mdash; 2026-07-15 Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/users.js merges OIDC logins into existing accounts when &hellip;
CVE-2026-53444 NONE Patched &mdash; 2026-07-15 Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in packages/wekan-oidc/oidc_server.js, server/models/org.js, and server/mode&hellip;