Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,173 CVEs

CVEs (3,173, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 176–200 of 3,173 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-48008 MEDIUM Patched 6.5 2026-07-17 Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL privilege can escalate to full administrator by cre…
CVE-2026-48009 MEDIUM Patched 6.8 2026-07-17 Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:read ACL can take over any admin account by triggering…
CVE-2026-48010 MEDIUM Patched 6.5 2026-07-17 Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framework/Api/Controller/UserController.php writes raw user…
CVE-2026-48014 MEDIUM Patched 6.5 2026-07-17 Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the order state transition features /api/_action/order/{orderId}/state/{transition} and similar tran…
CVE-2026-48015 MEDIUM Patched 4.9 2026-07-17 Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelist in src/Core/Framework/Resources/config/packages/sh…
CVE-2026-48016 MEDIUM Patched 4.3 2026-07-17 Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the Store API endpoint /store-api/handle-payment in src/Core/Checkout/Payment/SalesChannel/HandlePay…
CVE-2026-50273 HIGH Patched 7.5 2026-07-17 Datadog .NET Tracer is a client library for Datadog APM for .NET applications. Prior to 3.43.0, Datadog tracing libraries that implement W3C baggage propagation parse incom…
CVE-2026-9198 CRITICAL 9.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code…
CVE-2026-9202 CRITICAL 9.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented …
CVE-2026-9762 HIGH 7.8 2026-07-17 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.
CVE-2026-16073 LOW 3.5 2026-07-17 A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function Star.text_to_image/NetworkRenderStrategy.render of th…
CVE-2026-45162 HIGH Patched 8.0 2026-07-17 Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore locations call PHP's unserialize() on data from databas…
CVE-2026-45309 NONE Patched — 2026-07-17 AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.0, …
CVE-2026-45703 MEDIUM Patched 6.4 2026-07-17 Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, the WordExport export flow in bundles/WordExportBundle/src/Controller/Tr…
CVE-2026-47180 MEDIUM Patched 6.5 2026-07-17 Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.5, DNSIncoming._decode_labels_at_offset recurses once per DNS-name compression p…
CVE-2026-47183 MEDIUM Patched 6.5 2026-07-17 Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.6, DNSIncoming._log_exception_debug and the four QuietLogger exception-dedup met…
CVE-2026-47184 MEDIUM Patched 6.5 2026-07-17 Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.7, DNSCache._async_add inserted every response record into cache, _expirations, …
CVE-2026-48045 MEDIUM Patched 6.5 2026-07-17 Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.12, AsyncListener.handle_query_or_defer retained every truncated TC-bit incoming…
CVE-2026-48487 NONE Patched — 2026-07-17 Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string and _read_string in src/zeroconf/_protocol/incoming.p…
CVE-2026-49835 MEDIUM Patched 5.9 2026-07-17 Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and ra…
CVE-2026-50185 NONE Patched — 2026-07-17 RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as branches by the compile…
CVE-2026-52746 HIGH Patched 7.5 2026-07-17 JSONata is a JSON query and transformation language. Prior to 2.2.0, malicious non-matching inputs to the $toMillis function can cause superlinear backtracking in the ISO-8…
CVE-2026-53712 NONE Patched — 2026-07-17 SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) authentication mechanisms. Pri…
CVE-2026-58195 HIGH Patched 8.8 2026-07-17 Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP server tools in src/mcp/standalone-stdio.ts, src/mcp/fastmcp/servers/claude-flow-sdk.t…
CVE-2026-9103 CRITICAL Patched 9.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The…