Search
29,735 CVEs · Medium severity
CVEs (29,735, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 29,735 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-81680 | MEDIUM | Patched | 4.0 | 2026-08-27 | openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re… |
| CVE-2026-80213 | MEDIUM | Patched | 4.0 | 2026-08-27 | An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length into a single octet without checking its range. A la… |
| CVE-2026-75421 | MEDIUM | 4.0 | 2026-08-25 | aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in the IOFile::getLine() function. | |
| CVE-2026-39113 | MEDIUM | 4.0 | 2026-08-25 | Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d… | |
| CVE-2026-76367 | MEDIUM | Patched | 4.0 | 2026-08-19 | In Splunk SOAR versions below 8.6.0, a user who holds the "Incident Commander" Splunk SOAR role could store JavaScript in a note and run it in the browser of another user w… |
| CVE-2026-70916 | MEDIUM | 4.0 | 2026-08-18 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easil… | |
| CVE-2026-70917 | MEDIUM | 4.0 | 2026-08-18 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easil… | |
| CVE-2026-70719 | MEDIUM | 4.0 | 2026-08-18 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily… | |
| CVE-2026-62584 | MEDIUM | 4.0 | 2026-08-18 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affec… | |
| CVE-2026-50126 | MEDIUM | 4.0 | 2026-08-18 | Adaguc-server is an open source geographical information system to visualize, combine, compare and share real-time meteorological, climatological and remote sensing data vi… | |
| CVE-2026-58560 | MEDIUM | 4.0 | 2026-08-17 | Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability. | |
| CVE-2026-58561 | MEDIUM | 4.0 | 2026-08-17 | Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability. | |
| CVE-2026-71390 | MEDIUM | Patched | 4.0 | 2026-08-11 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerabil… |
| CVE-2026-71381 | MEDIUM | 4.0 | 2026-08-07 | Adobe Genuine Software Integrity Service on Windows is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker coul… | |
| CVE-2024-10302 | MEDIUM | 4.0 | 2026-08-06 | The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within … | |
| CVE-2026-70595 | MEDIUM | Patched | 4.0 | 2026-08-05 | Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticat… |
| CVE-2026-56569 | MEDIUM | 4.0 | 2026-07-31 | HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or applicat… | |
| CVE-2026-18018 | MEDIUM | Patched | 4.0 | 2026-07-30 | Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium s… |
| CVE-2026-65069 | MEDIUM | Patched | 4.0 | 2026-07-21 | Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in dsu.h… |
| CVE-2026-16266 | MEDIUM | Patched | 4.0 | 2026-07-21 | Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript proto… |
| CVE-2026-47085 | MEDIUM | 4.0 | 2026-07-16 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim'… | |
| CVE-2026-58553 | MEDIUM | 4.0 | 2026-07-15 | Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | |
| CVE-2026-58550 | MEDIUM | 4.0 | 2026-07-15 | Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | |
| CVE-2026-58549 | MEDIUM | 4.0 | 2026-07-15 | Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | |
| CVE-2026-14902 | MEDIUM | Patched | 4.0 | 2026-07-14 | An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs. |