Search
907 CVEs · Medium severity
CVEs (907, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 907 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-65069 | MEDIUM | Patched | 4.0 | 2026-07-21 | Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in dsu.h… |
| CVE-2026-16266 | MEDIUM | Patched | 4.0 | 2026-07-21 | Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript proto… |
| CVE-2026-48013 | MEDIUM | Patched | 4.1 | 2026-07-23 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side… |
| CVE-2026-60938 | MEDIUM | 4.1 | 2026-07-21 | Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15… | |
| CVE-2026-60832 | MEDIUM | 4.1 | 2026-07-21 | Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.… | |
| CVE-2026-60191 | MEDIUM | 4.1 | 2026-07-21 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4… | |
| CVE-2026-63744 | MEDIUM | Patched | 4.1 | 2026-07-20 | SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redirects without re-validating redirect targets against n… |
| CVE-2026-63736 | MEDIUM | Patched | 4.1 | 2026-07-20 | SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates only the URL hostname string against allow-lists without chec… |
| CVE-2026-65699 | MEDIUM | 4.2 | 2026-07-23 | AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent ru… | |
| CVE-2026-13068 | MEDIUM | 4.2 | 2026-07-22 | An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongo… | |
| CVE-2026-62489 | MEDIUM | 4.2 | 2026-07-21 | Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2… | |
| CVE-2026-61123 | MEDIUM | 4.2 | 2026-07-21 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficu… | |
| CVE-2026-60760 | MEDIUM | 4.2 | 2026-07-21 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.… | |
| CVE-2026-60709 | MEDIUM | 4.2 | 2026-07-21 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Diff… | |
| CVE-2026-12548 | MEDIUM | 4.2 | 2026-07-21 | A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause th… | |
| CVE-2026-47122 | MEDIUM | 4.2 | 2026-07-21 | Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `shouldAcceptNewConnection:` only enforces `SUCodeSig… | |
| CVE-2026-16212 | MEDIUM | 4.2 | 2026-07-19 | A vulnerability was identified in awesto django-shop up to 1.2.4. Affected is an unknown function of the file shop/models/inventory.py of the component Purchase Stock Handl… | |
| CVE-2026-21761 | MEDIUM | 4.2 | 2026-07-17 | HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentiall… | |
| CVE-2024-23578 | MEDIUM | 4.2 | 2026-07-17 | HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any … | |
| CVE-2024-23572 | MEDIUM | 4.2 | 2026-07-17 | HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the cont… | |
| CVE-2026-48012 | MEDIUM | 4.3 | 2026-07-23 | Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO entry point at `GET /api/oauth/sso/auth`. When the e… | |
| CVE-2026-65920 | MEDIUM | Patched | 4.3 | 2026-07-23 | Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitra… |
| CVE-2026-8287 | MEDIUM | 4.3 | 2026-07-23 | Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive… | |
| CVE-2026-65535 | MEDIUM | 4.3 | 2026-07-23 | Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions. | |
| CVE-2026-65537 | MEDIUM | 4.3 | 2026-07-23 | Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions. |