Search
9,825 CVEs
EOL hidden · Show all products
CVEs (9,825, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 9,825 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-47668 | CRITICAL | 10.0 | 2026-07-23 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection … | |
| CVE-2026-44210 | NONE | — | 2026-07-23 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0… | |
| CVE-2026-65761 | NONE | — | 2026-07-23 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated S… | |
| CVE-2026-65760 | NONE | — | 2026-07-23 | Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in us… | |
| CVE-2026-65759 | NONE | — | 2026-07-23 | Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, ar… | |
| CVE-2026-65698 | MEDIUM | 5.3 | 2026-07-23 | Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside th… | |
| CVE-2026-65697 | MEDIUM | 6.1 | 2026-07-23 | Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that allows unauthenticated attackers to inject a javasc… | |
| CVE-2026-65696 | MEDIUM | 5.4 | 2026-07-23 | Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, re… | |
| CVE-2026-65695 | MEDIUM | 6.8 | 2026-07-23 | Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filename argument to read ar… | |
| CVE-2026-44909 | HIGH | 7.5 | 2026-07-23 | Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by sett… | |
| CVE-2026-16768 | MEDIUM | 5.3 | 2026-07-23 | A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to im… | |
| CVE-2026-65917 | HIGH | Patched | 8.8 | 2026-07-23 | CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup hand… |
| CVE-2026-65916 | HIGH | Patched | 8.1 | 2026-07-23 | CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kil… |
| CVE-2026-48539 | MEDIUM | Patched | 5.4 | 2026-07-23 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authenticated attackers to inj… |
| CVE-2026-48538 | MEDIUM | Patched | 5.4 | 2026-07-23 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configuration that allows authenticated attackers to inject ar… |
| CVE-2026-48537 | MEDIUM | Patched | 5.4 | 2026-07-23 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configuration that allows authenticated attackers to inject arb… |
| CVE-2026-48536 | MEDIUM | Patched | 5.4 | 2026-07-23 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated attackers to inject arbi… |
| CVE-2026-48535 | MEDIUM | Patched | 5.4 | 2026-07-23 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configuration that allows authenticated attackers to inject arb… |
| CVE-2026-48534 | MEDIUM | Patched | 5.4 | 2026-07-23 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers to inject arbitrary web … |
| CVE-2026-48533 | NONE | — | 2026-07-23 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-48532 | MEDIUM | Patched | 5.4 | 2026-07-23 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy configuration that allows authenticated attackers to inj… |
| CVE-2026-48531 | MEDIUM | Patched | 5.4 | 2026-07-23 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attackers to inject arbitrary… |
| CVE-2026-48530 | MEDIUM | Patched | 5.4 | 2026-07-23 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration that allows authenticated attackers to inject arbit… |
| CVE-2026-16584 | HIGH | Patched | 7.0 | 2026-07-23 | Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execu… |
| CVE-2026-15617 | NONE | — | 2026-07-23 | Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-differen… |