Search
3,173 CVEs
CVEs (3,173, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 176–200 of 3,173 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-48008 | MEDIUM | Patched | 6.5 | 2026-07-17 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL privilege can escalate to full administrator by cre… |
| CVE-2026-48009 | MEDIUM | Patched | 6.8 | 2026-07-17 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:read ACL can take over any admin account by triggering… |
| CVE-2026-48010 | MEDIUM | Patched | 6.5 | 2026-07-17 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framework/Api/Controller/UserController.php writes raw user… |
| CVE-2026-48014 | MEDIUM | Patched | 6.5 | 2026-07-17 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the order state transition features /api/_action/order/{orderId}/state/{transition} and similar tran… |
| CVE-2026-48015 | MEDIUM | Patched | 4.9 | 2026-07-17 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelist in src/Core/Framework/Resources/config/packages/sh… |
| CVE-2026-48016 | MEDIUM | Patched | 4.3 | 2026-07-17 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the Store API endpoint /store-api/handle-payment in src/Core/Checkout/Payment/SalesChannel/HandlePay… |
| CVE-2026-50273 | HIGH | Patched | 7.5 | 2026-07-17 | Datadog .NET Tracer is a client library for Datadog APM for .NET applications. Prior to 3.43.0, Datadog tracing libraries that implement W3C baggage propagation parse incom… |
| CVE-2026-9198 | CRITICAL | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code… | |
| CVE-2026-9202 | CRITICAL | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented … | |
| CVE-2026-9762 | HIGH | 7.8 | 2026-07-17 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control. | |
| CVE-2026-16073 | LOW | 3.5 | 2026-07-17 | A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function Star.text_to_image/NetworkRenderStrategy.render of th… | |
| CVE-2026-45162 | HIGH | Patched | 8.0 | 2026-07-17 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore locations call PHP's unserialize() on data from databas… |
| CVE-2026-45309 | NONE | Patched | — | 2026-07-17 | AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.0, … |
| CVE-2026-45703 | MEDIUM | Patched | 6.4 | 2026-07-17 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, the WordExport export flow in bundles/WordExportBundle/src/Controller/Tr… |
| CVE-2026-47180 | MEDIUM | Patched | 6.5 | 2026-07-17 | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.5, DNSIncoming._decode_labels_at_offset recurses once per DNS-name compression p… |
| CVE-2026-47183 | MEDIUM | Patched | 6.5 | 2026-07-17 | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.6, DNSIncoming._log_exception_debug and the four QuietLogger exception-dedup met… |
| CVE-2026-47184 | MEDIUM | Patched | 6.5 | 2026-07-17 | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.7, DNSCache._async_add inserted every response record into cache, _expirations, … |
| CVE-2026-48045 | MEDIUM | Patched | 6.5 | 2026-07-17 | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.12, AsyncListener.handle_query_or_defer retained every truncated TC-bit incoming… |
| CVE-2026-48487 | NONE | Patched | — | 2026-07-17 | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string and _read_string in src/zeroconf/_protocol/incoming.p… |
| CVE-2026-49835 | MEDIUM | Patched | 5.9 | 2026-07-17 | Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and ra… |
| CVE-2026-50185 | NONE | Patched | — | 2026-07-17 | RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as branches by the compile… |
| CVE-2026-52746 | HIGH | Patched | 7.5 | 2026-07-17 | JSONata is a JSON query and transformation language. Prior to 2.2.0, malicious non-matching inputs to the $toMillis function can cause superlinear backtracking in the ISO-8… |
| CVE-2026-53712 | NONE | Patched | — | 2026-07-17 | SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) authentication mechanisms. Pri… |
| CVE-2026-58195 | HIGH | Patched | 8.8 | 2026-07-17 | Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP server tools in src/mcp/standalone-stdio.ts, src/mcp/fastmcp/servers/claude-flow-sdk.t… |
| CVE-2026-9103 | CRITICAL | Patched | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The… |