Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

9,841 CVEs

CVEs (9,841, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 126–150 of 9,841 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9147 HIGH 7.8 2026-07-18 uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (f…
CVE-2026-9145 MEDIUM 6.5 2026-07-02 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via the create_entry_el() function in versions up to, an…
CVE-2026-9140 NONE — 2026-07-14 A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to beco…
CVE-2026-9135 CRITICAL Patched 9.9 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies…
CVE-2026-9132 MEDIUM Patched 6.5 2026-06-30 A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private repositories they did n…
CVE-2026-9128 NONE — 2026-07-14 A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified…
CVE-2026-9127 NONE — 2026-07-14 A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated us…
CVE-2026-9108 NONE — 2026-07-14 A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize …
CVE-2026-9107 MEDIUM 6.4 2026-07-01 The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field_components]' parameter…
CVE-2026-9106 MEDIUM Patched 5.5 2026-06-30 A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner mana…
CVE-2026-9105 MEDIUM Patched 6.5 2026-06-29 An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafte…
CVE-2026-9103 CRITICAL Patched 9.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The…
CVE-2026-9099 HIGH Patched 7.7 2026-06-25 A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited adm…
CVE-2026-9086 HIGH Patched 7.3 2026-06-25 A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to client registration endpoint…
CVE-2026-9085 HIGH Patched 8.8 2026-07-05 Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-Parental-Cont…
CVE-2026-9083 MEDIUM Patched 4.9 2026-06-25 A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore par…
CVE-2026-9080 HIGH Patched 7.3 2026-07-03 Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using …
CVE-2026-9079 CRITICAL Patched 9.8 2026-07-03 libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent tra…
CVE-2026-9074 CRITICAL Patched 9.1 2026-07-08 IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
CVE-2026-9066 MEDIUM Patched 6.1 2026-07-23 The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of Java…
CVE-2026-9046 HIGH 7.0 2026-07-16 A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, tha…
CVE-2026-9028 MEDIUM 5.3 2026-07-09 The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.7.4. This is due to the plugin …
CVE-2026-9027 MEDIUM 5.3 2026-07-09 The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification of Cryptographic Signature in all versions up to, a…
CVE-2026-9021 MEDIUM 5.3 2026-07-09 The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. This is due to the plugin registering the easy_invoic…
CVE-2026-9017 MEDIUM 5.3 2026-07-11 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to t…