Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,163 CVEs

CVEs (3,163, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 76–100 of 3,163 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-15379 NONE — 2026-07-17 The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the SYSTEM account, bypass…
CVE-2026-15380 NONE — 2026-07-17 A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3)
CVE-2026-9656 MEDIUM 4.3 2026-07-17 The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.…
CVE-2026-62764 NONE Patched — 2026-07-17 Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user without system permissions may issue a remote comma…
CVE-2026-22104 NONE — 2026-07-17 Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of a…
CVE-2026-16008 MEDIUM 6.3 2026-07-17 A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parsePropertyDependencies of the file src/keywords/propert…
CVE-2026-59252 NONE Patched — 2026-07-17 Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet, resulting in denial of service for …
CVE-2026-59694 NONE Patched — 2026-07-17 Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per payment by a large multipl…
CVE-2026-59695 NONE Patched — 2026-07-17 Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by naming an arb…
CVE-2026-8075 MEDIUM 6.5 2026-07-17 Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user to crash anot&hellip;
CVE-2026-9602 MEDIUM 6.5 2026-07-17 Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to &hellip;
CVE-2026-15943 MEDIUM 5.5 2026-07-17 A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an&hellip;
CVE-2026-16009 MEDIUM 6.3 2026-07-17 A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /prescriptionorderdetail.php. The manipulation of t&hellip;
CVE-2026-16013 MEDIUM 5.3 2026-07-17 A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. Affected by this issue is the function CipAppPath::deserialize_symbolic&hellip;
CVE-2026-13082 MEDIUM 5.3 2026-07-17 GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. The random method creates the challenge text used for the CAPTCHA by sampling characters fro&hellip;
CVE-2026-13410 HIGH 8.2 2026-07-17 Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled.&hellip;
CVE-2026-16014 HIGH 7.3 2026-07-17 A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the component Login Form. Performing a manipulation of the ar&hellip;
CVE-2026-7189 HIGH 7.5 2026-07-17 Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs. T&hellip;
CVE-2026-8396 HIGH Patched 7.5 2026-07-17 Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Data External Linking. This issue affects NetGIS: from&hellip;
CVE-2024-23564 CRITICAL 9.1 2026-07-17 HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to th&hellip;
CVE-2024-23565 MEDIUM 5.3 2026-07-17 HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b &hellip;
CVE-2024-23566 MEDIUM 6.5 2026-07-17 HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force , autom&hellip;
CVE-2024-23567 MEDIUM 4.3 2026-07-17 HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data&hellip;
CVE-2024-23568 MEDIUM 5.3 2026-07-17 HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information of soft&hellip;
CVE-2024-23569 MEDIUM 4.3 2026-07-17 HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header