Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,173 CVEs

CVEs (3,173, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 126–150 of 3,173 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-14741 HIGH Patched 7.5 2026-07-17 HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date. parse_date() matches the date string against a chain of alte…
CVE-2026-14871 NONE — 2026-07-17 osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem.
CVE-2026-15007 NONE Patched — 2026-07-17 A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository releas…
CVE-2026-15343 NONE Patched — 2026-07-17 A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write f…
CVE-2026-15783 NONE Patched — 2026-07-17 A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata fro…
CVE-2026-58148 NONE — 2026-07-17 Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to an unauthenticated sto…
CVE-2026-58149 MEDIUM 5.3 2026-07-17 Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration &hellip;
CVE-2026-60024 CRITICAL 9.8 2026-07-17 Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow u&hellip;
CVE-2026-60025 HIGH 8.8 2026-07-17 Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpo&hellip;
CVE-2026-63095 MEDIUM 6.5 2026-07-17 Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party iden&hellip;
CVE-2026-63096 MEDIUM 5.8 2026-07-17 Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound TLS connections to a&hellip;
CVE-2026-63097 MEDIUM 4.3 2026-07-17 Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/routing/context.go) that allows authenticated local user&hellip;
CVE-2026-63098 MEDIUM 5.3 2026-07-17 TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by se&hellip;
CVE-2026-63099 MEDIUM 6.5 2026-07-17 TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated user to access attachme&hellip;
CVE-2026-63100 MEDIUM 6.5 2026-07-17 Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role users to access and modify global hosting settings by&hellip;
CVE-2026-9537 MEDIUM Patched 5.3 2026-07-17 Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature to the recom&hellip;
CVE-2026-11763 MEDIUM 6.5 2026-07-17 Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Managem&hellip;
CVE-2026-12691 HIGH Patched 7.5 2026-07-17 Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Pla&hellip;
CVE-2026-12692 CRITICAL Patched 9.8 2026-07-17 Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0&hellip;
CVE-2026-12693 CRITICAL Patched 9.4 2026-07-17 Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. &hellip;
CVE-2026-12694 CRITICAL Patched 9.1 2026-07-17 Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterpri&hellip;
CVE-2026-16093 MEDIUM 5.4 2026-07-17 Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was d&hellip;
CVE-2026-16103 MEDIUM 4.3 2026-07-17 A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Cl&hellip;
CVE-2026-16104 MEDIUM 4.3 2026-07-17 A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access&hellip;
CVE-2026-16106 MEDIUM 4.9 2026-07-17 A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a chil&hellip;