Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

66,694 CVEs

EOL hidden · Show all products

CVEs (66,694, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 51–75 of 66,694 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-48012 MEDIUM 4.3 2026-07-23 Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO entry point at `GET /api/oauth/sso/auth`. When the e…
CVE-2026-47722 NONE — 2026-07-23 nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `internal/configgen/generator.go:86,108,119` interpolates …
CVE-2026-47670 NONE — 2026-07-23 DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can …
CVE-2026-47669 NONE — 2026-07-23 DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not val…
CVE-2026-25800 HIGH 7.5 2026-07-23 Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and prior to version 0.11.15, the `Assembler` component…
CVE-2026-15212 HIGH 8.8 2026-07-23 The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_req…
CVE-2026-12353 MEDIUM 5.3 2026-07-23 An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending o…
CVE-2026-65010 MEDIUM Patched 6.6 2026-07-23 Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that allows local attackers to write arbitrary files by pr…
CVE-2026-63765 HIGH Patched 8.2 2026-07-23 Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStor…
CVE-2026-16756 HIGH Patched 7.5 2026-07-23 Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote a…
CVE-2026-15687 LOW 2.4 2026-07-23 A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new files in arbitrary locations on the client machine e…
CVE-2026-6516 CRITICAL Patched 10.0 2026-07-23 Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
CVE-2026-65920 MEDIUM Patched 4.3 2026-07-23 Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitra…
CVE-2026-65919 HIGH Patched 7.5 2026-07-23 Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-suppli…
CVE-2026-65918 HIGH Patched 7.1 2026-07-23 PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes un…
CVE-2026-65763 NONE — 2026-07-23 Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 1.0.0-6.0.9 - Improper validation of user inputs lead to a reflective XSS vulnerability.
CVE-2026-65762 NONE — 2026-07-23 Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 1.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XSS vulnerability.
CVE-2026-65702 HIGH 8.6 2026-07-23 Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated remote attackers to write…
CVE-2026-65701 CRITICAL 9.1 2026-07-23 SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote att…
CVE-2026-65700 CRITICAL 9.8 2026-07-23 h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbi…
CVE-2026-65699 MEDIUM 4.2 2026-07-23 AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent ru…
CVE-2026-47769 MEDIUM 5.3 2026-07-23 APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Prior to commit 7f19b52280f414f57af2b79a95333d1c8fbeec…
CVE-2026-47755 MEDIUM 6.5 2026-07-23 ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can ret…
CVE-2026-47752 CRITICAL 9.9 2026-07-23 Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notifica…
CVE-2026-47743 HIGH 8.7 2026-07-23 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stor…