Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,163 CVEs

CVEs (3,163, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 101–125 of 3,163 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2024-23570 MEDIUM 4.3 2026-07-17 HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on …
CVE-2024-23571 MEDIUM 4.3 2026-07-17 HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields sh…
CVE-2024-23572 MEDIUM 4.2 2026-07-17 HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the cont…
CVE-2024-23573 LOW 3.7 2026-07-17 HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.…
CVE-2024-23574 MEDIUM 5.3 2026-07-17 HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. U…
CVE-2024-23575 MEDIUM 5.3 2026-07-17 HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may …
CVE-2024-23577 MEDIUM 4.3 2026-07-17 HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol. When an appl…
CVE-2024-23578 MEDIUM 4.2 2026-07-17 HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any …
CVE-2024-42214 MEDIUM 5.3 2026-07-17 HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by…
CVE-2025-60357 HIGH 8.1 2026-07-17 AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEvent/list endpoint.
CVE-2026-16015 MEDIUM 6.3 2026-07-17 A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app/api/v1/tasks.py of the…
CVE-2026-16016 HIGH 7.3 2026-07-17 A vulnerability was identified in poco-ai poco-claw up to 0.5.4. This issue affects the function run_task of the file executor/app/api/v1/task.py. The manipulation of the a…
CVE-2026-16072 MEDIUM 4.9 2026-07-17 A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-…
CVE-2026-51080 CRITICAL 9.8 2026-07-17 libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.
CVE-2026-7488 HIGH 7.5 2026-07-17 Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This issue affects E-Commerce: …
CVE-2026-9592 NONE — 2026-07-17 SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is …
CVE-2026-12705 MEDIUM Patched 6.4 2026-07-17 Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE). This issue affects KNX Update Tool (ABB): through 2.0.175; KNX U…
CVE-2026-16017 MEDIUM 6.3 2026-07-17 A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. Impacted is the function list/remove of the file tools/tool_cron.go of the component cron Chat Tool. Th…
CVE-2026-16089 MEDIUM 5.4 2026-07-17 A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the clien…
CVE-2026-51081 MEDIUM 6.1 2026-07-17 A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows attackers to execute arbit…
CVE-2026-51082 HIGH Patched 7.2 2026-07-17 A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x be…
CVE-2026-51083 MEDIUM Patched 6.5 2026-07-17 Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privileges to obtain hashed pass…
CVE-2026-63093 HIGH 8.8 2026-07-17 Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe f…
CVE-2026-63094 HIGH 8.1 2026-07-17 SigNoz through 0.133.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on…
CVE-2026-12715 NONE — 2026-07-17 Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code…