Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

23,172 CVEs

CVEs (23,172, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 176–200 of 23,172 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9782 HIGH Patched 8.8 2026-06-25 Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in…
CVE-2026-9781 HIGH Patched 8.8 2026-06-25 Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected inst…
CVE-2026-9780 HIGH Patched 8.8 2026-06-25 Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected i…
CVE-2026-9779 HIGH Patched 7.2 2026-06-24 ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execu…
CVE-2026-9778 HIGH Patched 7.2 2026-06-24 ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected insta…
CVE-2026-9777 HIGH Patched 7.2 2026-06-24 ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installation…
CVE-2026-9776 HIGH Patched 7.5 2026-06-24 ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive inform…
CVE-2026-9775 MEDIUM Patched 6.5 2026-06-24 ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installati…
CVE-2026-9774 MEDIUM Patched 6.5 2026-06-24 ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected instal…
CVE-2026-9773 HIGH Patched 8.8 2026-06-24 Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal…
CVE-2026-9772 HIGH Patched 8.8 2026-06-24 Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install…
CVE-2026-9770 NONE — 2026-07-15 Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices.  An attacker with access to th…
CVE-2026-9762 HIGH 7.8 2026-07-17 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.
CVE-2026-9759 MEDIUM Patched 5.5 2026-05-27 ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service
CVE-2026-9758 HIGH 7.3 2026-06-10 Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to be considered trusted
CVE-2026-9757 HIGH 7.5 2026-05-30 The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlatlng' and 'nelatlng' parameters in all versions up to, and including, 4.5.5 The parameters ar…
CVE-2026-9756 MEDIUM 6.4 2026-07-03 The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute in all versions up to, an…
CVE-2026-9754 MEDIUM Patched 6.5 2026-06-09 An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command
CVE-2026-9753 HIGH Patched 8.1 2026-06-09 The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash …
CVE-2026-9752 MEDIUM Patched 6.5 2026-06-09 An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a str…
CVE-2026-9751 MEDIUM Patched 5.5 2026-06-09 The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
CVE-2026-9750 MEDIUM Patched 6.5 2026-06-09 An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query ex…
CVE-2026-9749 MEDIUM Patched 6.5 2026-06-09 This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-preserving delivery. If a …
CVE-2026-9748 MEDIUM Patched 6.5 2026-06-09 The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index stats conversion failed. But PauseExecution is not a g…
CVE-2026-9747 MEDIUM Patched 6.5 2026-06-09 Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.