Search
23,283 CVEs · High severity
EOL hidden · Show all products
CVEs (23,283, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 23,283 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-40430 | HIGH | 7.5 | 2026-07-23 | Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API. | |
| CVE-2026-28698 | HIGH | 8.6 | 2026-07-23 | Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the under… | |
| CVE-2026-65694 | HIGH | 7.5 | 2026-07-23 | Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by … | |
| CVE-2026-65604 | HIGH | 8.2 | 2026-07-23 | Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body e… | |
| CVE-2026-63313 | HIGH | Patched | 7.7 | 2026-07-23 | 9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controlled url parameter and pa… |
| CVE-2026-16765 | HIGH | 7.3 | 2026-07-23 | A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unknown functionality of the file /OnlineClassroom/loginlinkadmin.php. Exec… | |
| CVE-2024-58355 | HIGH | Patched | 8.9 | 2026-07-23 | Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking view (e.g., https://app.cal.com/booking/<id>) rende… |
| CVE-2024-58353 | HIGH | Patched | 8.9 | 2026-07-23 | Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly accessible single booking view (e.g., /booking/<id>). … |
| CVE-2026-50039 | HIGH | 7.5 | 2026-07-23 | The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corruption via a Read Request. | |
| CVE-2026-50032 | HIGH | 7.5 | 2026-07-23 | A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a WriteRequest with an e… | |
| CVE-2026-49035 | HIGH | 8.1 | 2026-07-23 | The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabl… | |
| CVE-2026-16796 | HIGH | Patched | 7.3 | 2026-07-23 | Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to… |
| CVE-2026-16002 | HIGH | 8.2 | 2026-07-23 | The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service. | |
| CVE-2026-15968 | HIGH | Patched | 7.1 | 2026-07-23 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before … |
| CVE-2026-15967 | HIGH | Patched | 7.5 | 2026-07-23 | Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. |
| CVE-2026-15966 | HIGH | Patched | 7.5 | 2026-07-23 | Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.… |
| CVE-2026-10697 | HIGH | Patched | 7.5 | 2026-07-23 | Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. |
| CVE-2026-65706 | HIGH | 7.8 | 2026-07-23 | FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a c… | |
| CVE-2026-65705 | HIGH | 7.8 | 2026-07-23 | FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a … | |
| CVE-2026-65704 | HIGH | 7.8 | 2026-07-23 | FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -s… | |
| CVE-2026-65703 | HIGH | 7.8 | 2026-07-23 | FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying … | |
| CVE-2026-60122 | HIGH | 7.8 | 2026-07-23 | gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to … | |
| CVE-2026-25800 | HIGH | 7.5 | 2026-07-23 | Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and prior to version 0.11.15, the `Assembler` component… | |
| CVE-2026-15212 | HIGH | 8.8 | 2026-07-23 | The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_req… | |
| CVE-2026-63765 | HIGH | Patched | 8.2 | 2026-07-23 | Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStor… |