Search
23,123 CVEs
EOL hidden · Show all products
CVEs (23,123, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 23,123 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42933 | CRITICAL | 10.0 | 2026-07-23 | Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypa… | |
| CVE-2025-71389 | CRITICAL | Patched | 10.0 | 2026-07-23 | Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) req… |
| CVE-2026-6516 | CRITICAL | Patched | 10.0 | 2026-07-23 | Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API. |
| CVE-2026-47668 | CRITICAL | 10.0 | 2026-07-23 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection … | |
| CVE-2026-64812 | CRITICAL | Patched | 10.0 | 2026-07-23 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session |
| CVE-2026-64813 | CRITICAL | Patched | 10.0 | 2026-07-23 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session |
| CVE-2026-59555 | CRITICAL | 10.0 | 2026-07-23 | Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. | |
| CVE-2026-60366 | CRITICAL | 10.0 | 2026-07-22 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a… | |
| CVE-2026-8984 | NONE | — | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test … | |
| CVE-2026-8985 | NONE | — | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can su… | |
| CVE-2026-60644 | CRITICAL | 10.0 | 2026-07-21 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 … | |
| CVE-2026-60389 | CRITICAL | 10.0 | 2026-07-21 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and … | |
| CVE-2026-60379 | CRITICAL | 10.0 | 2026-07-21 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and … | |
| CVE-2026-60358 | CRITICAL | 10.0 | 2026-07-21 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and … | |
| CVE-2026-60360 | CRITICAL | 10.0 | 2026-07-21 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.… | |
| CVE-2026-60365 | CRITICAL | 10.0 | 2026-07-21 | Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). The … | |
| CVE-2026-60217 | CRITICAL | 10.0 | 2026-07-21 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 an… | |
| CVE-2026-47056 | CRITICAL | 10.0 | 2026-07-21 | Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.… | |
| CVE-2026-8982 | NONE | — | 2026-07-21 | Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on d… | |
| CVE-2026-8983 | NONE | — | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An atta… | |
| CVE-2026-16367 | CRITICAL | Patched | 10.0 | 2026-07-21 | Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-61424 | NONE | — | 2026-07-20 | Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenti… | |
| CVE-2026-61900 | NONE | — | 2026-07-20 | Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated … | |
| CVE-2026-46412 | CRITICAL | 10.0 | 2026-07-20 | @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an att… | |
| CVE-2026-44359 | CRITICAL | 10.0 | 2026-07-20 | Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_req… |