Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,163 CVEs

CVEs (3,163, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 51–75 of 3,163 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-8169 NONE — 2026-07-20 ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The challenge value is generated using an insufficiently ra…
CVE-2026-8152 NONE — 2026-07-22 Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack. When Unblu Spark is deployed with com.unblu.id…
CVE-2026-8082 HIGH Patched 7.5 2026-07-21 The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowin…
CVE-2026-8075 MEDIUM 6.5 2026-07-17 Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user to crash anot&hellip;
CVE-2026-8056 HIGH Patched 8.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the parameter f&hellip;
CVE-2026-7872 HIGH Patched 7.5 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user.
CVE-2026-7771 MEDIUM 5.5 2026-07-17 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted statements containing subqueries could lead to a denial &hellip;
CVE-2026-7755 HIGH Patched 8.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files.
CVE-2026-7754 HIGH Patched 7.7 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the &hellip;
CVE-2026-7667 HIGH Patched 8.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted Co&hellip;
CVE-2026-7534 HIGH 7.2 2026-07-23 The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions &hellip;
CVE-2026-7488 HIGH 7.5 2026-07-17 Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This issue affects E-Commerce: &hellip;
CVE-2026-7364 LOW 3.1 2026-07-17 IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Sec&hellip;
CVE-2026-7328 NONE &mdash; 2026-07-22 Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode allows a privileged lo&hellip;
CVE-2026-7232 HIGH 7.2 2026-07-23 The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due to ins&hellip;
CVE-2026-7189 HIGH 7.5 2026-07-17 Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs. T&hellip;
CVE-2026-7120 MEDIUM Patched 5.3 2026-07-23 @fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to an&hellip;
CVE-2026-6952 HIGH 7.2 2026-07-21 A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could a&hellip;
CVE-2026-6924 NONE &mdash; 2026-07-23 A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of n&hellip;
CVE-2026-6793 MEDIUM Patched 5.4 2026-07-20 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS.&hellip;
CVE-2026-6792 MEDIUM 6.5 2026-07-21 Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCit&hellip;
CVE-2026-6656 HIGH 7.5 2026-07-20 Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This allows discrepancies in tim&hellip;
CVE-2026-65920 MEDIUM Patched 4.3 2026-07-23 Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitra&hellip;
CVE-2026-65919 HIGH Patched 7.5 2026-07-23 Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-suppli&hellip;
CVE-2026-65918 HIGH Patched 7.1 2026-07-23 PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes un&hellip;