Search
66,771 CVEs
CVEs (66,771, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 51–75 of 66,771 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13089 | NONE | — | 2026-07-22 | OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify. When the caller does not pin… | |
| CVE-2025-44090 | NONE | — | 2026-07-22 | An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file. | |
| CVE-2025-50324 | NONE | — | 2026-07-22 | An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component. | |
| CVE-2025-50325 | NONE | — | 2026-07-22 | BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affec… | |
| CVE-2025-50327 | NONE | — | 2026-07-22 | An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web prote… | |
| CVE-2025-50329 | NONE | — | 2026-07-22 | An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe. | |
| CVE-2025-50330 | NONE | — | 2026-07-22 | An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe. | |
| CVE-2025-44089 | NONE | — | 2026-07-22 | An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file. | |
| CVE-2026-14899 | NONE | Patched | — | 2026-07-22 | The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be … |
| CVE-2026-16624 | NONE | — | 2026-07-22 | Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then ste… | |
| CVE-2026-16157 | NONE | — | 2026-07-22 | Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Installing the software outside of the Program Files d… | |
| CVE-2026-16552 | NONE | — | 2026-07-22 | Rejected reason: The reported issue is invalid, as it requires root privileges to reproduce, and it is out of scope of the threat model of the affected component. | |
| CVE-2026-14985 | NONE | — | 2026-07-22 | The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper privilege del… | |
| CVE-2026-16415 | NONE | — | 2026-07-21 | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) v… | |
| CVE-2026-16416 | NONE | — | 2026-07-21 | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chr… | |
| CVE-2026-16417 | NONE | — | 2026-07-21 | Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafte… | |
| CVE-2026-16418 | NONE | — | 2026-07-21 | Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium… | |
| CVE-2026-16419 | NONE | — | 2026-07-21 | Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HT… | |
| CVE-2026-16420 | NONE | — | 2026-07-21 | Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium … | |
| CVE-2026-16421 | NONE | — | 2026-07-21 | Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML pa… | |
| CVE-2026-16413 | NONE | — | 2026-07-21 | Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox es… | |
| CVE-2026-16414 | NONE | — | 2026-07-21 | Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malic… | |
| CVE-2026-65065 | NONE | Patched | — | 2026-07-21 | Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in roa… |
| CVE-2026-64616 | NONE | Patched | — | 2026-07-21 | Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ndarray.h… |
| CVE-2026-16392 | NONE | Patched | — | 2026-07-21 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |