Search
8,720 CVEs · Medium severity
CVEs (8,720, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 8,720 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-51385 | MEDIUM | 6.9 | 2026-07-20 | An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fetch, _build_opener, _fet… | |
| CVE-2026-53935 | MEDIUM | Patched | 6.9 | 2026-07-07 | Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLoc… |
| CVE-2026-13083 | MEDIUM | Patched | 6.9 | 2026-06-26 | A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An attacker with cluster adm… |
| CVE-2026-47693 | MEDIUM | 6.9 | 2026-06-23 | Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 are vulnerable to CSV Injection (Formula Injection) in its log expo… | |
| CVE-2026-56411 | MEDIUM | Patched | 6.9 | 2026-06-21 | xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations. |
| CVE-2026-56408 | MEDIUM | Patched | 6.9 | 2026-06-21 | libexpat before 2.8.2 has an integer overflow in copyString. |
| CVE-2026-56410 | MEDIUM | Patched | 6.9 | 2026-06-21 | xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. |
| CVE-2026-56404 | MEDIUM | Patched | 6.9 | 2026-06-21 | libexpat before 2.8.2 has an integer overflow in addBinding. |
| CVE-2026-56405 | MEDIUM | Patched | 6.9 | 2026-06-21 | libexpat before 2.8.2 has an integer overflow in getAttributeId. |
| CVE-2026-56406 | MEDIUM | Patched | 6.9 | 2026-06-21 | libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse. |
| CVE-2026-56407 | MEDIUM | Patched | 6.9 | 2026-06-21 | libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen. |
| CVE-2026-56403 | MEDIUM | Patched | 6.9 | 2026-06-21 | libexpat before 2.8.2 has an integer overflow in storeAtts. |
| CVE-2026-56132 | MEDIUM | Patched | 6.9 | 2026-06-19 | In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-struc… |
| CVE-2026-46361 | MEDIUM | Patched | 6.9 | 2026-05-15 | phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in search.twig where result.question and result.answerPreview are rendered with the raw filter, d… |
| CVE-2026-37503 | MEDIUM | Patched | 6.9 | 2026-05-01 | Cross-Site Scripting (XSS) in V2Board thru 1.7.4. The custom_html field in theme configuration is rendered using Blade unescaped output in public/theme/v2board/dashboard.bl… |
| CVE-2026-50044 | MEDIUM | 6.8 | 2026-07-23 | Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin credentials via weak hash o… | |
| CVE-2026-65695 | MEDIUM | 6.8 | 2026-07-23 | Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filename argument to read ar… | |
| CVE-2026-6390 | MEDIUM | 6.8 | 2026-07-23 | A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted f… | |
| CVE-2026-16615 | MEDIUM | 6.8 | 2026-07-22 | A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number ge… | |
| CVE-2026-10723 | MEDIUM | 6.8 | 2026-07-22 | BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.1… | |
| CVE-2026-62559 | MEDIUM | 6.8 | 2026-07-21 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily … | |
| CVE-2026-61134 | MEDIUM | 6.8 | 2026-07-21 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Diff… | |
| CVE-2026-60862 | MEDIUM | 6.8 | 2026-07-21 | Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2… | |
| CVE-2026-60795 | MEDIUM | 6.8 | 2026-07-21 | Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.… | |
| CVE-2026-60744 | MEDIUM | 6.8 | 2026-07-21 | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. D… |