Search
3,163 CVEs
CVEs (3,163, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 3,163 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-50329 | NONE | — | 2026-07-22 | An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe. | |
| CVE-2025-50330 | NONE | — | 2026-07-22 | An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe. | |
| CVE-2025-44089 | NONE | — | 2026-07-22 | An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file. | |
| CVE-2026-14899 | NONE | Patched | — | 2026-07-22 | The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be … |
| CVE-2026-13058 | NONE | — | 2026-07-22 | An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with an incomplete set of re… | |
| CVE-2026-22049 | NONE | — | 2026-07-22 | ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when su… | |
| CVE-2026-16624 | NONE | — | 2026-07-22 | Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then ste… | |
| CVE-2026-16157 | NONE | — | 2026-07-22 | Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Installing the software outside of the Program Files d… | |
| CVE-2026-7328 | NONE | — | 2026-07-22 | Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode allows a privileged lo… | |
| CVE-2026-16552 | NONE | — | 2026-07-22 | Rejected reason: The reported issue is invalid, as it requires root privileges to reproduce, and it is out of scope of the threat model of the affected component. | |
| CVE-2026-14985 | NONE | — | 2026-07-22 | The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper privilege del… | |
| CVE-2026-53910 | NONE | Patched | — | 2026-07-22 | diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in m… |
| CVE-2026-50243 | NONE | — | 2026-07-22 | In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect… | |
| CVE-2026-50252 | NONE | — | 2026-07-22 | In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transaction… | |
| CVE-2026-8152 | NONE | — | 2026-07-22 | Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack. When Unblu Spark is deployed with com.unblu.id… | |
| CVE-2026-16270 | NONE | Patched | — | 2026-07-22 | Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex to a field. When someone provide the proper string … |
| CVE-2026-65598 | NONE | Patched | — | 2026-07-22 | n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass path restrictions by sw… |
| CVE-2026-65599 | NONE | Patched | — | 2026-07-22 | n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google Service Account key, the full PEM private key wa… |
| CVE-2026-65600 | NONE | Patched | — | 2026-07-22 | Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v3.7.6 contain an authentication bypass via path traversal in the ReplacePathRegex middleware. When Rep… |
| CVE-2026-65601 | NONE | Patched | — | 2026-07-22 | Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[]… |
| CVE-2026-65602 | NONE | Patched | — | 2026-07-22 | Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references (the allo… |
| CVE-2026-65591 | NONE | Patched | — | 2026-07-22 | n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions… |
| CVE-2026-65592 | NONE | Patched | — | 2026-07-22 | n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cach… |
| CVE-2026-65593 | NONE | Patched | — | 2026-07-22 | n8n versions before 1.123.64 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated atta… |
| CVE-2026-65594 | NONE | Patched | — | 2026-07-22 | n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated … |