Search
3,173 CVEs
CVEs (3,173, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 126–150 of 3,173 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-14741 | HIGH | Patched | 7.5 | 2026-07-17 | HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date. parse_date() matches the date string against a chain of alte… |
| CVE-2026-14871 | NONE | — | 2026-07-17 | osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem. | |
| CVE-2026-15007 | NONE | Patched | — | 2026-07-17 | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository releas… |
| CVE-2026-15343 | NONE | Patched | — | 2026-07-17 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write f… |
| CVE-2026-15783 | NONE | Patched | — | 2026-07-17 | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata fro… |
| CVE-2026-58148 | NONE | — | 2026-07-17 | Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to an unauthenticated sto… | |
| CVE-2026-58149 | MEDIUM | 5.3 | 2026-07-17 | Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration … | |
| CVE-2026-60024 | CRITICAL | 9.8 | 2026-07-17 | Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow u… | |
| CVE-2026-60025 | HIGH | 8.8 | 2026-07-17 | Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpo… | |
| CVE-2026-63095 | MEDIUM | 6.5 | 2026-07-17 | Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party iden… | |
| CVE-2026-63096 | MEDIUM | 5.8 | 2026-07-17 | Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound TLS connections to a… | |
| CVE-2026-63097 | MEDIUM | 4.3 | 2026-07-17 | Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/routing/context.go) that allows authenticated local user… | |
| CVE-2026-63098 | MEDIUM | 5.3 | 2026-07-17 | TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by se… | |
| CVE-2026-63099 | MEDIUM | 6.5 | 2026-07-17 | TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated user to access attachme… | |
| CVE-2026-63100 | MEDIUM | 6.5 | 2026-07-17 | Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role users to access and modify global hosting settings by… | |
| CVE-2026-9537 | MEDIUM | Patched | 5.3 | 2026-07-17 | Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature to the recom… |
| CVE-2026-11763 | MEDIUM | 6.5 | 2026-07-17 | Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Managem… | |
| CVE-2026-12691 | HIGH | Patched | 7.5 | 2026-07-17 | Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Pla… |
| CVE-2026-12692 | CRITICAL | Patched | 9.8 | 2026-07-17 | Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0… |
| CVE-2026-12693 | CRITICAL | Patched | 9.4 | 2026-07-17 | Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. … |
| CVE-2026-12694 | CRITICAL | Patched | 9.1 | 2026-07-17 | Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterpri… |
| CVE-2026-16093 | MEDIUM | 5.4 | 2026-07-17 | Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was d… | |
| CVE-2026-16103 | MEDIUM | 4.3 | 2026-07-17 | A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Cl… | |
| CVE-2026-16104 | MEDIUM | 4.3 | 2026-07-17 | A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access… | |
| CVE-2026-16106 | MEDIUM | 4.9 | 2026-07-17 | A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a chil… |