Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 126–150 of 30,217 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9588 | NONE | — | 2026-07-17 | A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_… | |
| CVE-2026-9587 | NONE | — | 2026-07-17 | An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through … | |
| CVE-2026-9586 | CRITICAL | Patched | 9.8 | 2026-07-17 | An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> … |
| CVE-2026-9585 | NONE | — | 2026-07-17 | An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly saniti… | |
| CVE-2026-9577 | MEDIUM | Patched | 4.8 | 2026-07-23 | The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?… |
| CVE-2026-9576 | MEDIUM | Patched | 4.9 | 2026-06-30 | The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users… |
| CVE-2026-9571 | MEDIUM | Patched | 5.9 | 2026-07-13 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivat… |
| CVE-2026-9563 | HIGH | 7.5 | 2026-07-02 | In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number of characters consumed while pars… | |
| CVE-2026-9561 | HIGH | Patched | 8.2 | 2026-07-14 | Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The or… |
| CVE-2026-9548 | MEDIUM | Patched | 6.5 | 2026-08-28 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows re… |
| CVE-2026-9547 | HIGH | Patched | 7.4 | 2026-07-03 | When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted serve… |
| CVE-2026-9546 | HIGH | Patched | 7.5 | 2026-07-03 | A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation states that passing NULL to `CURLOPT_REFERER` … |
| CVE-2026-9545 | HIGH | Patched | 7.5 | 2026-07-03 | In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the atta… |
| CVE-2026-9539 | MEDIUM | 6.5 | 2026-06-24 | An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 on hypervisor host environmen… | |
| CVE-2026-9537 | MEDIUM | Patched | 5.3 | 2026-07-17 | Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature to the recom… |
| CVE-2026-9507 | NONE | — | 2026-06-16 | A session fixation vulnerability has been identified in osTicket v1.18.2. This security flaw allows an attacker to hijack a victim’s account by keeping the initial session … | |
| CVE-2026-9499 | NONE | — | 2026-07-21 | An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated … | |
| CVE-2026-9494 | MEDIUM | 5.5 | 2026-07-16 | An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executin… | |
| CVE-2026-9492 | HIGH | 7.8 | 2026-07-13 | The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated… | |
| CVE-2026-9491 | MEDIUM | Patched | 4.3 | 2026-08-28 | A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive information. |
| CVE-2026-9487 | CRITICAL | Patched | 9.1 | 2026-08-03 | XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolves the SignedInfo Refere… |
| CVE-2026-9390 | CRITICAL | Patched | 9.1 | 2026-08-03 | XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions by concatenating the Si… |
| CVE-2026-9375 | NONE | — | 2026-06-19 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-9341 | MEDIUM | 4.3 | 2026-07-14 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc… | |
| CVE-2026-9335 | MEDIUM | 6.5 | 2026-08-02 | A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The `KerasFileEdi… |