Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

26,633 CVEs · Medium severity

CVEs (26,633, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 26,633 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-51385 MEDIUM 6.9 2026-07-20 An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fetch, _build_opener, _fet…
CVE-2026-53935 MEDIUM Patched 6.9 2026-07-07 Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLoc…
CVE-2026-13083 MEDIUM Patched 6.9 2026-06-26 A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An attacker with cluster adm…
CVE-2026-47693 MEDIUM 6.9 2026-06-23 Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 are vulnerable to CSV Injection (Formula Injection) in its log expo…
CVE-2026-56411 MEDIUM Patched 6.9 2026-06-21 xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
CVE-2026-56408 MEDIUM Patched 6.9 2026-06-21 libexpat before 2.8.2 has an integer overflow in copyString.
CVE-2026-56410 MEDIUM Patched 6.9 2026-06-21 xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
CVE-2026-56404 MEDIUM Patched 6.9 2026-06-21 libexpat before 2.8.2 has an integer overflow in addBinding.
CVE-2026-56405 MEDIUM Patched 6.9 2026-06-21 libexpat before 2.8.2 has an integer overflow in getAttributeId.
CVE-2026-56406 MEDIUM Patched 6.9 2026-06-21 libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
CVE-2026-56407 MEDIUM Patched 6.9 2026-06-21 libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
CVE-2026-56403 MEDIUM Patched 6.9 2026-06-21 libexpat before 2.8.2 has an integer overflow in storeAtts.
CVE-2026-56132 MEDIUM Patched 6.9 2026-06-19 In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-struc…
CVE-2026-46361 MEDIUM Patched 6.9 2026-05-15 phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in search.twig where result.question and result.answerPreview are rendered with the raw filter, d…
CVE-2026-37503 MEDIUM Patched 6.9 2026-05-01 Cross-Site Scripting (XSS) in V2Board thru 1.7.4. The custom_html field in theme configuration is rendered using Blade unescaped output in public/theme/v2board/dashboard.bl…
CVE-2026-41238 MEDIUM 6.9 2026-04-23 DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. Whe…
CVE-2026-41527 MEDIUM Patched 6.9 2026-04-21 KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a Kleopatra user, because there is an error in the mechanism (KUniqueService) for ens…
CVE-2026-41253 MEDIUM Patched 6.9 2026-04-18 In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains a malicious file whose name is va…
CVE-2026-39963 MEDIUM Patched 6.9 2026-04-15 Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the serendipity_setCookie() function in include/functions_config.inc.php uses $_SERVER['HTTP_H…
CVE-2026-37980 MEDIUM 6.9 2026-04-14 A flaw was found in Keycloak, specifically in the organization selection login page. A remote attacker with `manage-realm` or `manage-organizations` administrative privileg…
CVE-2026-40446 MEDIUM 6.9 2026-04-13 Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.This issue affects Escargot: 97e8115…
CVE-2026-28553 MEDIUM 6.9 2026-04-13 Vulnerability of improper permission control in the theme setting module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-34530 MEDIUM Patched 6.9 2026-04-01 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the SPA in…
CVE-2026-32041 MEDIUM Patched 6.9 2026-03-19 OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowing browser-control routes to remain accessible without aut…
CVE-2025-68482 MEDIUM Patched 6.9 2026-03-10 A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnaly…