Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,911 CVEs · High severity

CVEs (3,911, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 151–175 of 3,911 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-62145 HIGH 7.5 2026-07-22 A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.
CVE-2026-55973 HIGH 7.5 2026-07-22 In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is…
CVE-2026-44690 HIGH 7.5 2026-07-22 In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NS…
CVE-2026-40691 HIGH 7.5 2026-07-22 In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound the reply length agains…
CVE-2026-32665 HIGH 7.5 2026-07-22 In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (strea…
CVE-2026-13190 HIGH 8.1 2026-07-22 In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenc…
CVE-2026-13189 HIGH 7.5 2026-07-22 In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence serv…
CVE-2026-13187 HIGH 8.1 2026-07-22 In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained …
CVE-2026-13186 HIGH 8.1 2026-07-22 In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key …
CVE-2026-13185 HIGH 8.1 2026-07-22 In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled co…
CVE-2026-13184 HIGH 7.5 2026-07-22 In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata inte…
CVE-2026-13183 HIGH 7.5 2026-07-22 In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, ena…
CVE-2026-13182 HIGH 7.5 2026-07-22 In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating a…
CVE-2026-13181 HIGH 8.1 2026-07-22 In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type reso…
CVE-2026-44191 HIGH 7.8 2026-07-22 A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executio…
CVE-2026-65603 HIGH Patched 8.8 2026-07-22 The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile self-update handler (processUserProfile(), the&hellip;
CVE-2026-61391 HIGH 7.2 2026-07-22 There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially cra&hellip;
CVE-2026-61390 HIGH 7.7 2026-07-22 There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.
CVE-2026-57600 HIGH 7.5 2026-07-22 Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.
CVE-2026-4773 HIGH Patched 8.1 2026-07-22 Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authentication Bypass. This issue affects IDM-MFA: from 2025.11&hellip;
CVE-2026-44190 HIGH 7.8 2026-07-22 A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized comm&hellip;
CVE-2026-44189 HIGH 7.8 2026-07-22 A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a mal&hellip;
CVE-2026-14551 HIGH 8.8 2026-07-22 The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-pr&hellip;
CVE-2026-63047 HIGH 7.5 2026-07-22 Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.&hellip;
CVE-2026-3821 HIGH 8.8 2026-07-22 Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attacker can exploit SMASH’s input capability to compromis&hellip;