Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,173 CVEs

CVEs (3,173, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 151–175 of 3,173 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-16108 MEDIUM 4.3 2026-07-17 A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned…
CVE-2026-21760 MEDIUM 4.6 2026-07-17 HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to …
CVE-2026-21761 MEDIUM 4.2 2026-07-17 HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentiall…
CVE-2026-21762 LOW 3.7 2026-07-17 HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections against common web-based attacks such as clickjacking,…
CVE-2026-21764 LOW 3.1 2026-07-17 HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restricted. This may result in unintended application behav…
CVE-2026-44722 MEDIUM Patched 6.2 2026-07-17 pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. Prior to 0.4.0, a Python operator precedence bug in pyzipper/zipfile_aes.py …
CVE-2026-49208 MEDIUM Patched 5.3 2026-07-17 Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as DateTimeInterface and no explicit format is configured, …
CVE-2026-49209 MEDIUM Patched 6.5 2026-07-17 Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller\BatchActionController::__invoke() iterates over the…
CVE-2026-49210 MEDIUM Patched 6.1 2026-07-17 Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\ChildComponentPartialRenderer::createHtml() interpolates …
CVE-2026-49211 HIGH Patched 7.5 2026-07-17 Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, Symfony\UX\Autocomplete\Doctrine\EntitySearchUtil::addSearchClause() builds the LIKE ex…
CVE-2026-49212 HIGH Patched 7.5 2026-07-17 Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\LiveComponent\LiveComponentHydrator covered only sorted…
CVE-2026-49215 MEDIUM Patched 5.4 2026-07-17 Symfony UX is a JavaScript ecosystem for Symfony. From 2.22.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\EventListener\LiveComponentSubscriber::isLiveComponentRequest…
CVE-2026-49216 MEDIUM Patched 5.4 2026-07-17 Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/ux-autocomplete renders AJAX response items in _crea…
CVE-2026-54496 CRITICAL Patched 9.3 2026-07-17 ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base sc…
CVE-2026-57860 HIGH 7.8 2026-07-17 ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined in a repository's .mcp.json file on startup without u…
CVE-2026-63101 HIGH 7.5 2026-07-17 Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers to export the complete member roster of any group, in…
CVE-2026-63307 MEDIUM Patched 6.5 2026-07-17 Chat2DB before 5.3.0 contains an insecure direct object reference vulnerability in the GET /api/connection/datasource/{id} endpoint. The handler calls dataSourceService.que…
CVE-2026-63308 MEDIUM Patched 4.3 2026-07-17 Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go that allows attackers to t…
CVE-2026-63309 MEDIUM Patched 4.3 2026-07-17 SurrealDB before 3.1.5 fail to apply field-level SELECT permissions to ORDER BY clauses, allowing authenticated users to leak the relative ordering of restricted field valu…
CVE-2026-8297 CRITICAL 9.8 2026-07-17 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Ser…
CVE-2026-9585 NONE — 2026-07-17 An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly saniti…
CVE-2026-9586 NONE &mdash; 2026-07-17 An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> &hellip;
CVE-2026-9587 NONE &mdash; 2026-07-17 An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through &hellip;
CVE-2026-9588 NONE &mdash; 2026-07-17 A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_&hellip;
CVE-2025-59866 LOW 3.3 2026-07-17 The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables any logged-in&hellip;