Search
133,141 CVEs · High severity
EOL hidden · Show all products
CVEs (133,141, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 126–150 of 133,141 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-60368 | HIGH | 8.8 | 2026-07-22 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a… | |
| CVE-2026-64829 | HIGH | 7.4 | 2026-07-22 | Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated acce… | |
| CVE-2026-14881 | HIGH | 7.8 | 2026-07-22 | When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it is possib… | |
| CVE-2026-13078 | HIGH | 7.7 | 2026-07-22 | A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls… | |
| CVE-2026-13077 | HIGH | 7.1 | 2026-07-22 | A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pipeline. The vulnerabili… | |
| CVE-2026-13072 | HIGH | 8.1 | 2026-07-22 | When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in m… | |
| CVE-2026-13059 | HIGH | 8.1 | 2026-07-22 | An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insuffici… | |
| CVE-2026-64835 | HIGH | 8.8 | 2026-07-22 | FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger … | |
| CVE-2026-64834 | HIGH | 7.5 | 2026-07-22 | FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause deni… | |
| CVE-2026-64833 | HIGH | 7.1 | 2026-07-22 | FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by suppl… | |
| CVE-2026-64832 | HIGH | 8.8 | 2026-07-22 | FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory… | |
| CVE-2026-65013 | HIGH | Patched | 8.8 | 2026-07-22 | Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate othe… |
| CVE-2026-64831 | HIGH | 8.8 | 2026-07-22 | FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addres… | |
| CVE-2026-64830 | HIGH | 8.8 | 2026-07-22 | FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supp… | |
| CVE-2026-49499 | HIGH | 8.8 | 2026-07-22 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with re… | |
| CVE-2026-40714 | HIGH | 7.2 | 2026-07-22 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attacker with remote access could poten… | |
| CVE-2026-16607 | HIGH | 7.8 | 2026-07-22 | A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for local privilege escalation to root of an alrea… | |
| CVE-2026-48029 | HIGH | 7.1 | 2026-07-22 | libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-co… | |
| CVE-2026-13321 | HIGH | 8.6 | 2026-07-22 | The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through… | |
| CVE-2026-13204 | HIGH | 7.5 | 2026-07-22 | If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpected… | |
| CVE-2026-12617 | HIGH | 7.5 | 2026-07-22 | The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client q… | |
| CVE-2026-11721 | HIGH | 7.5 | 2026-07-22 | It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `na… | |
| CVE-2026-11622 | HIGH | 7.5 | 2026-07-22 | A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to sen… | |
| CVE-2026-11605 | HIGH | 7.5 | 2026-07-22 | The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly need… | |
| CVE-2026-11331 | HIGH | 7.5 | 2026-07-22 | An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during R… |