Search
3,163 CVEs
CVEs (3,163, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 51–75 of 3,163 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8169 | NONE | — | 2026-07-20 | ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The challenge value is generated using an insufficiently ra… | |
| CVE-2026-8152 | NONE | — | 2026-07-22 | Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack. When Unblu Spark is deployed with com.unblu.id… | |
| CVE-2026-8082 | HIGH | Patched | 7.5 | 2026-07-21 | The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowin… |
| CVE-2026-8075 | MEDIUM | 6.5 | 2026-07-17 | Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user to crash anot… | |
| CVE-2026-8056 | HIGH | Patched | 8.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the parameter f… |
| CVE-2026-7872 | HIGH | Patched | 7.5 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user. |
| CVE-2026-7771 | MEDIUM | 5.5 | 2026-07-17 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted statements containing subqueries could lead to a denial … | |
| CVE-2026-7755 | HIGH | Patched | 8.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files. |
| CVE-2026-7754 | HIGH | Patched | 7.7 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the … |
| CVE-2026-7667 | HIGH | Patched | 8.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted Co… |
| CVE-2026-7534 | HIGH | 7.2 | 2026-07-23 | The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions … | |
| CVE-2026-7488 | HIGH | 7.5 | 2026-07-17 | Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This issue affects E-Commerce: … | |
| CVE-2026-7364 | LOW | 3.1 | 2026-07-17 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Sec… | |
| CVE-2026-7328 | NONE | — | 2026-07-22 | Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode allows a privileged lo… | |
| CVE-2026-7232 | HIGH | 7.2 | 2026-07-23 | The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due to ins… | |
| CVE-2026-7189 | HIGH | 7.5 | 2026-07-17 | Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs. T… | |
| CVE-2026-7120 | MEDIUM | Patched | 5.3 | 2026-07-23 | @fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to an… |
| CVE-2026-6952 | HIGH | 7.2 | 2026-07-21 | A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could a… | |
| CVE-2026-6924 | NONE | — | 2026-07-23 | A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of n… | |
| CVE-2026-6793 | MEDIUM | Patched | 5.4 | 2026-07-20 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS.… |
| CVE-2026-6792 | MEDIUM | 6.5 | 2026-07-21 | Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCit… | |
| CVE-2026-6656 | HIGH | 7.5 | 2026-07-20 | Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This allows discrepancies in tim… | |
| CVE-2026-65920 | MEDIUM | Patched | 4.3 | 2026-07-23 | Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitra… |
| CVE-2026-65919 | HIGH | Patched | 7.5 | 2026-07-23 | Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-suppli… |
| CVE-2026-65918 | HIGH | Patched | 7.1 | 2026-07-23 | PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes un… |