Search
23,162 CVEs
CVEs (23,162, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 151–175 of 23,162 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21579 | NONE | Patched | — | 2026-07-21 | This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluen… |
| CVE-2026-16243 | NONE | — | 2026-07-21 | In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if the number of bytes to compare is zero. | |
| CVE-2026-16439 | NONE | — | 2026-07-21 | In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow. | |
| CVE-2026-47407 | NONE | — | 2026-07-21 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources under `/api/v1/workspaces… | |
| CVE-2026-47397 | NONE | — | 2026-07-21 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidden metadata in a webpage causes PraisonAI agents to write attacker-controlled content to arbitrary pat… | |
| CVE-2026-15792 | NONE | — | 2026-07-21 | A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. | |
| CVE-2026-15793 | NONE | — | 2026-07-21 | BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could l… | |
| CVE-2026-15829 | NONE | — | 2026-07-21 | A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox… | |
| CVE-2026-15432 | NONE | — | 2026-07-21 | When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows an attacker to use tim… | |
| CVE-2026-15789 | NONE | — | 2026-07-21 | A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid… | |
| CVE-2026-15791 | NONE | — | 2026-07-21 | A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside … | |
| CVE-2026-47394 | NONE | — | 2026-07-21 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is incomplete. The original advisory description named fo… | |
| CVE-2026-46681 | NONE | — | 2026-07-21 | @nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.0, the _copyProps function in lib/src/object/copy.ts uses for...in to it… | |
| CVE-2026-9499 | NONE | — | 2026-07-21 | An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated … | |
| CVE-2026-16392 | NONE | Patched | — | 2026-07-21 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-64627 | NONE | Patched | — | 2026-07-21 | Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerability. When the GraphQL API is mounted with public intro… |
| CVE-2026-8593 | NONE | Patched | — | 2026-07-21 | Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to … |
| CVE-2023-37507 | NONE | — | 2026-07-21 | HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed. | |
| CVE-2023-37508 | NONE | — | 2026-07-21 | HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain browser weaknesses are present. | |
| CVE-2026-57495 | NONE | — | 2026-07-20 | AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to version 0.1.33, @agentic… | |
| CVE-2026-57494 | NONE | — | 2026-07-20 | AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated AgenticMail agent can enumer… | |
| CVE-2026-47134 | NONE | — | 2026-07-20 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. The ECDSA private key used to sign the on-disk policy database (`/Libra… | |
| CVE-2026-47133 | NONE | — | 2026-07-20 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 5.0.10, each table in the on-disk SQLite policy store … | |
| CVE-2026-44510 | NONE | — | 2026-07-20 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users sh… | |
| CVE-2026-64650 | NONE | — | 2026-07-20 | The `@ai-sdk/harness-opencode` tool is an HarnessV1 adapter backed by @openai/codex-sdk, which drives the codex command line interface. Prior to version 1.0.29, the tool re… |