Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

907 CVEs · Medium severity

CVEs (907, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 907 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-65069 MEDIUM Patched 4.0 2026-07-21 Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in dsu.h…
CVE-2026-16266 MEDIUM Patched 4.0 2026-07-21 Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript proto…
CVE-2026-48013 MEDIUM Patched 4.1 2026-07-23 Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side…
CVE-2026-60938 MEDIUM 4.1 2026-07-21 Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15…
CVE-2026-60832 MEDIUM 4.1 2026-07-21 Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.…
CVE-2026-60191 MEDIUM 4.1 2026-07-21 Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4…
CVE-2026-63744 MEDIUM Patched 4.1 2026-07-20 SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redirects without re-validating redirect targets against n…
CVE-2026-63736 MEDIUM Patched 4.1 2026-07-20 SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates only the URL hostname string against allow-lists without chec…
CVE-2026-65699 MEDIUM 4.2 2026-07-23 AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent ru…
CVE-2026-13068 MEDIUM 4.2 2026-07-22 An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongo…
CVE-2026-62489 MEDIUM 4.2 2026-07-21 Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2…
CVE-2026-61123 MEDIUM 4.2 2026-07-21 Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficu…
CVE-2026-60760 MEDIUM 4.2 2026-07-21 Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.…
CVE-2026-60709 MEDIUM 4.2 2026-07-21 Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Diff…
CVE-2026-12548 MEDIUM 4.2 2026-07-21 A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause th…
CVE-2026-47122 MEDIUM 4.2 2026-07-21 Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `shouldAcceptNewConnection:` only enforces `SUCodeSig…
CVE-2026-16212 MEDIUM 4.2 2026-07-19 A vulnerability was identified in awesto django-shop up to 1.2.4. Affected is an unknown function of the file shop/models/inventory.py of the component Purchase Stock Handl…
CVE-2026-21761 MEDIUM 4.2 2026-07-17 HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentiall…
CVE-2024-23578 MEDIUM 4.2 2026-07-17 HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any …
CVE-2024-23572 MEDIUM 4.2 2026-07-17 HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the cont…
CVE-2026-48012 MEDIUM 4.3 2026-07-23 Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO entry point at `GET /api/oauth/sso/auth`. When the e…
CVE-2026-65920 MEDIUM Patched 4.3 2026-07-23 Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitra…
CVE-2026-8287 MEDIUM 4.3 2026-07-23 Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive…
CVE-2026-65535 MEDIUM 4.3 2026-07-23 Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
CVE-2026-65537 MEDIUM 4.3 2026-07-23 Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.