Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

18,975 CVEs

EOL hidden · Show all products

CVEs (18,975, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 76–100 of 18,975 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-25855 HIGH 8.8 2026-06-08 OpenBullet2 through version 0.3.2 contains a remote code execution vulnerability that allows authenticated users to execute arbitrary commands by uploading script files (.b…
CVE-2026-25559 HIGH 8.8 2026-06-08 OpenBullet2 through version 0.3.2 contains a path traversal vulnerability in the wordlist endpoint that allows authenticated attackers to perform arbitrary file read, write…
CVE-2026-25555 CRITICAL 9.8 2026-06-08 OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain adm…
CVE-2026-11611 MEDIUM 6.5 2026-06-08 A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading syn…
CVE-2026-11534 LOW 3.5 2026-06-08 A vulnerability was detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this issue is some unknown functionality of t…
CVE-2026-11533 MEDIUM 5.4 2026-06-08 A security vulnerability has been detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this vulnerability is an unknow…
CVE-2026-11532 MEDIUM 6.3 2026-06-08 A weakness has been identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected is an unknown function of the file /add.php of…
CVE-2026-11531 HIGH 7.3 2026-06-08 A security flaw has been discovered in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This impacts an unknown function of the file admin…
CVE-2026-11530 HIGH 7.3 2026-06-08 A vulnerability was identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This affects an unknown function of the file /index.ph …
CVE-2026-49975 NONE — 2026-06-08 Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apach…
CVE-2026-49756 NONE Patched — 2026-06-08 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in wojtekmach Req allows multipart parameter smuggling via attacker-influenced part metadata. Re…
CVE-2026-49755 NONE Patched — 2026-06-08 Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in wojtekmach Req allows attacker-controlled HTTP servers to exhaust memory in a Req client v…
CVE-2026-48913 HIGH 7.3 2026-06-08 Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
CVE-2026-48488 NONE — 2026-06-08 phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a cryptographically broken algorithm. SHA-1 has been vu…
CVE-2026-46657 HIGH 7.1 2026-06-08 Bludit is a content management system. Versions prior to 3.22.0 have a vulnerability in the user management logic that allows deactivated accounts to maintain access via pe…
CVE-2026-46656 HIGH 8.8 2026-06-08 Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remain valid even after the corresponding user accou…
CVE-2026-46480 NONE Patched — 2026-06-08 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluator create and update mass-assignment allows cross-wo…
CVE-2026-46479 NONE Patched — 2026-06-08 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluation create and update mass-assignment allows cross-w…
CVE-2026-46478 NONE Patched — 2026-06-08 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, DatasetRow create and update mass-assignment allows cross-w…
CVE-2026-46477 NONE Patched — 2026-06-08 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, dataset create and update mass-assignment allows cross-work…
CVE-2026-46476 NONE Patched — 2026-06-08 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, CustomTemplate create and update mass-assignment allows cro…
CVE-2026-46475 NONE Patched — 2026-06-08 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, assistant create and update mass-assignment allows cross-wo…
CVE-2026-46444 NONE Patched — 2026-06-08 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all CRUD endpoints for OpenAI Assistants Vector Store have …
CVE-2026-46443 NONE Patched — 2026-06-08 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when credentials are fetched with a credentialName filter p…
CVE-2026-46442 NONE Patched — 2026-06-08 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authori…