Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

26,633 CVEs · Medium severity

CVEs (26,633, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 26,633 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-65069 MEDIUM Patched 4.0 2026-07-21 Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in dsu.h…
CVE-2026-16266 MEDIUM Patched 4.0 2026-07-21 Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript proto…
CVE-2026-47085 MEDIUM 4.0 2026-07-16 An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim'…
CVE-2026-58553 MEDIUM 4.0 2026-07-15 Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-58550 MEDIUM 4.0 2026-07-15 Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-58549 MEDIUM 4.0 2026-07-15 Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-14902 MEDIUM 4.0 2026-07-14 An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs.
CVE-2026-56360 MEDIUM Patched 4.0 2026-07-08 n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send un…
CVE-2026-13199 MEDIUM 4.0 2026-07-07 EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resulted in consistent kernel addresses across boots and …
CVE-2026-55688 MEDIUM Patched 4.0 2026-07-01 The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In versions from 2.0.0 prior to 2.16.0…
CVE-2026-53945 MEDIUM Patched 4.0 2026-06-24 Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing an …
CVE-2026-57053 MEDIUM Patched 4.0 2026-06-23 GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code i…
CVE-2026-56357 MEDIUM Patched 4.0 2026-06-22 n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to implement HMAC-SHA256 signature verification. Attack…
CVE-2026-45536 MEDIUM Patched 4.0 2026-06-12 Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets ms…
CVE-2026-53464 MEDIUM Patched 4.0 2026-06-10 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, when providing invalid options to the wand option …
CVE-2026-46559 MEDIUM Patched 4.0 2026-06-10 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an incorrect check in the JP2 will …
CVE-2026-41714 MEDIUM Patched 4.0 2026-06-10 Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no ce…
CVE-2026-10998 MEDIUM Patched 4.0 2026-06-04 Out of bounds read in Media in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform an out of bounds memory read via malicious n…
CVE-2019-25734 MEDIUM 4.0 2026-06-04 Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that allows unauthenticated attackers to include arbitrary …
CVE-2021-4479 MEDIUM 4.0 2026-06-02 Dräger Atlan A350 versions 1.00 up to and including 1.01 contains an improper input handling vulnerability that allows attackers to cause a denial of service by sending spe…
CVE-2019-25723 MEDIUM 4.0 2026-06-02 Dräger Perseus A500 software versions 2.00 through 2.02 contains an improper input handling vulnerability that allows external attackers to cause a denial of service by sen…
CVE-2026-28581 MEDIUM 4.0 2026-06-01 In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local w…
CVE-2026-10099 MEDIUM 4.0 2026-05-29 XX-Net V5.16.6 contains a WebSocket frame parsing vulnerability in the WebSocket_receive_worker routine of simple_http_server.py that allows attackers to cause corrupted ap…
CVE-2026-21785 MEDIUM 4.0 2026-05-27 A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, all…
CVE-2026-47104 MEDIUM Patched 4.0 2026-05-27 libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service …