Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 126–150 of 30,217 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18452 | CRITICAL | 10.0 | 2026-07-31 | DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control o… | |
| CVE-2026-66803 | CRITICAL | 10.0 | 2026-07-30 | Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. | |
| CVE-2026-48449 | CRITICAL | Patched | 10.0 | 2026-07-30 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Explo… |
| CVE-2026-67429 | CRITICAL | Patched | 10.0 | 2026-07-29 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir … |
| CVE-2026-16326 | CRITICAL | Patched | 10.0 | 2026-07-29 | In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be us… |
| CVE-2026-54735 | CRITICAL | Patched | 10.0 | 2026-07-29 | Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpola… |
| CVE-2026-58162 | CRITICAL | Patched | 10.0 | 2026-07-29 | The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1… |
| CVE-2026-57834 | CRITICAL | Patched | 10.0 | 2026-07-29 | Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.… |
| CVE-2026-58150 | CRITICAL | Patched | 10.0 | 2026-07-29 | Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 thro… |
| CVE-2026-33267 | CRITICAL | Patched | 10.0 | 2026-07-29 | Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users a… |
| CVE-2026-16498 | CRITICAL | Patched | 10.0 | 2026-07-28 | The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user… |
| CVE-2026-65880 | NONE | — | 2026-07-28 | Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that in… | |
| CVE-2026-11756 | CRITICAL | 10.0 | 2026-07-28 | A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R202… | |
| CVE-2026-16812 | CRITICAL | Patched | 10.0 | 2026-07-27 | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. … |
| CVE-2026-66012 | CRITICAL | 10.0 | 2026-07-25 | SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no … | |
| CVE-2026-58630 | CRITICAL | 10.0 | 2026-07-24 | Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-57106 | CRITICAL | 10.0 | 2026-07-24 | Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-56163 | CRITICAL | 10.0 | 2026-07-24 | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-62825 | CRITICAL | 10.0 | 2026-07-24 | Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-58275 | CRITICAL | 10.0 | 2026-07-24 | Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-56191 | CRITICAL | 10.0 | 2026-07-24 | Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. | |
| CVE-2026-42933 | CRITICAL | 10.0 | 2026-07-23 | Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypa… | |
| CVE-2025-71389 | CRITICAL | Patched | 10.0 | 2026-07-23 | Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) req… |
| CVE-2026-6516 | CRITICAL | Patched | 10.0 | 2026-07-23 | Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API. |
| CVE-2026-47668 | CRITICAL | 10.0 | 2026-07-23 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection … |