Search
9,841 CVEs
CVEs (9,841, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 126–150 of 9,841 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9147 | HIGH | 7.8 | 2026-07-18 | uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (f… | |
| CVE-2026-9145 | MEDIUM | 6.5 | 2026-07-02 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via the create_entry_el() function in versions up to, an… | |
| CVE-2026-9140 | NONE | — | 2026-07-14 | A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to beco… | |
| CVE-2026-9135 | CRITICAL | Patched | 9.9 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies… |
| CVE-2026-9132 | MEDIUM | Patched | 6.5 | 2026-06-30 | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private repositories they did n… |
| CVE-2026-9128 | NONE | — | 2026-07-14 | A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified… | |
| CVE-2026-9127 | NONE | — | 2026-07-14 | A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated us… | |
| CVE-2026-9108 | NONE | — | 2026-07-14 | A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize … | |
| CVE-2026-9107 | MEDIUM | 6.4 | 2026-07-01 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field_components]' parameter… | |
| CVE-2026-9106 | MEDIUM | Patched | 5.5 | 2026-06-30 | A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner mana… |
| CVE-2026-9105 | MEDIUM | Patched | 6.5 | 2026-06-29 | An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafte… |
| CVE-2026-9103 | CRITICAL | Patched | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The… |
| CVE-2026-9099 | HIGH | Patched | 7.7 | 2026-06-25 | A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited adm… |
| CVE-2026-9086 | HIGH | Patched | 7.3 | 2026-06-25 | A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to client registration endpoint… |
| CVE-2026-9085 | HIGH | Patched | 8.8 | 2026-07-05 | Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-Parental-Cont… |
| CVE-2026-9083 | MEDIUM | Patched | 4.9 | 2026-06-25 | A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore par… |
| CVE-2026-9080 | HIGH | Patched | 7.3 | 2026-07-03 | Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using … |
| CVE-2026-9079 | CRITICAL | Patched | 9.8 | 2026-07-03 | libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent tra… |
| CVE-2026-9074 | CRITICAL | Patched | 9.1 | 2026-07-08 | IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality. |
| CVE-2026-9066 | MEDIUM | Patched | 6.1 | 2026-07-23 | The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of Java… |
| CVE-2026-9046 | HIGH | 7.0 | 2026-07-16 | A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, tha… | |
| CVE-2026-9028 | MEDIUM | 5.3 | 2026-07-09 | The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.7.4. This is due to the plugin … | |
| CVE-2026-9027 | MEDIUM | 5.3 | 2026-07-09 | The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification of Cryptographic Signature in all versions up to, a… | |
| CVE-2026-9021 | MEDIUM | 5.3 | 2026-07-09 | The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. This is due to the plugin registering the easy_invoic… | |
| CVE-2026-9017 | MEDIUM | 5.3 | 2026-07-11 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to t… |