Search
907 CVEs · Medium severity
CVEs (907, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 907 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-51385 | MEDIUM | 6.9 | 2026-07-20 | An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fetch, _build_opener, _fet… | |
| CVE-2026-50044 | MEDIUM | 6.8 | 2026-07-23 | Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin credentials via weak hash o… | |
| CVE-2026-65695 | MEDIUM | 6.8 | 2026-07-23 | Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filename argument to read ar… | |
| CVE-2026-6390 | MEDIUM | 6.8 | 2026-07-23 | A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted f… | |
| CVE-2026-16615 | MEDIUM | 6.8 | 2026-07-22 | A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number ge… | |
| CVE-2026-10723 | MEDIUM | 6.8 | 2026-07-22 | BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.1… | |
| CVE-2026-62559 | MEDIUM | 6.8 | 2026-07-21 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily … | |
| CVE-2026-61134 | MEDIUM | 6.8 | 2026-07-21 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Diff… | |
| CVE-2026-60862 | MEDIUM | 6.8 | 2026-07-21 | Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2… | |
| CVE-2026-60795 | MEDIUM | 6.8 | 2026-07-21 | Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.… | |
| CVE-2026-60744 | MEDIUM | 6.8 | 2026-07-21 | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. D… | |
| CVE-2026-60687 | MEDIUM | 6.8 | 2026-07-21 | Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12… | |
| CVE-2026-60666 | MEDIUM | 6.8 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficul… | |
| CVE-2026-60612 | MEDIUM | 6.8 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Commonline Loans). The supported version that is affected is 9.2.38. … | |
| CVE-2026-47045 | MEDIUM | 6.8 | 2026-07-21 | Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vuln… | |
| CVE-2026-15927 | MEDIUM | 6.8 | 2026-07-21 | A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference paramete… | |
| CVE-2026-59776 | MEDIUM | Patched | 6.8 | 2026-07-21 | Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the… |
| CVE-2026-54497 | MEDIUM | Patched | 6.8 | 2026-07-17 | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base instances ret… |
| CVE-2026-12283 | MEDIUM | Patched | 6.8 | 2026-07-17 | Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allo… |
| CVE-2026-48009 | MEDIUM | Patched | 6.8 | 2026-07-17 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:read ACL can take over any admin account by triggering… |
| CVE-2026-27377 | MEDIUM | 6.7 | 2026-07-23 | Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions. | |
| CVE-2026-46737 | MEDIUM | 6.7 | 2026-07-22 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote ac… | |
| CVE-2026-62503 | MEDIUM | 6.7 | 2026-07-21 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Ea… | |
| CVE-2026-61176 | MEDIUM | 6.7 | 2026-07-21 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. … | |
| CVE-2026-61182 | MEDIUM | 6.7 | 2026-07-21 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Data Import). The supported version that is affected… |