Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,163 CVEs

CVEs (3,163, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 76–100 of 3,163 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2025-50329 NONE — 2026-07-22 An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.
CVE-2025-50330 NONE — 2026-07-22 An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.
CVE-2025-44089 NONE — 2026-07-22 An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
CVE-2026-14899 NONE Patched — 2026-07-22 The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be …
CVE-2026-13058 NONE — 2026-07-22 An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with an incomplete set of re…
CVE-2026-22049 NONE — 2026-07-22 ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when su…
CVE-2026-16624 NONE — 2026-07-22 Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then ste…
CVE-2026-16157 NONE — 2026-07-22 Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Installing the software outside of the Program Files d…
CVE-2026-7328 NONE — 2026-07-22 Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode allows a privileged lo…
CVE-2026-16552 NONE — 2026-07-22 Rejected reason: The reported issue is invalid, as it requires root privileges to reproduce, and it is out of scope of the threat model of the affected component.
CVE-2026-14985 NONE — 2026-07-22 The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper privilege del…
CVE-2026-53910 NONE Patched — 2026-07-22 diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in m…
CVE-2026-50243 NONE — 2026-07-22 In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect…
CVE-2026-50252 NONE — 2026-07-22 In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transaction…
CVE-2026-8152 NONE — 2026-07-22 Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack. When Unblu Spark is deployed with com.unblu.id…
CVE-2026-16270 NONE Patched — 2026-07-22 Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex to a field. When someone provide the proper string …
CVE-2026-65598 NONE Patched — 2026-07-22 n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass path restrictions by sw…
CVE-2026-65599 NONE Patched — 2026-07-22 n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google Service Account key, the full PEM private key wa…
CVE-2026-65600 NONE Patched &mdash; 2026-07-22 Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v3.7.6 contain an authentication bypass via path traversal in the ReplacePathRegex middleware. When Rep&hellip;
CVE-2026-65601 NONE Patched &mdash; 2026-07-22 Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[]&hellip;
CVE-2026-65602 NONE Patched &mdash; 2026-07-22 Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references (the allo&hellip;
CVE-2026-65591 NONE Patched &mdash; 2026-07-22 n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions&hellip;
CVE-2026-65592 NONE Patched &mdash; 2026-07-22 n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cach&hellip;
CVE-2026-65593 NONE Patched &mdash; 2026-07-22 n8n versions before 1.123.64 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated atta&hellip;
CVE-2026-65594 NONE Patched &mdash; 2026-07-22 n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated &hellip;