Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,909 CVEs · High severity

EOL hidden · Show all products

CVEs (3,909, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 3,909 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-40430 HIGH 7.5 2026-07-23 Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API.
CVE-2026-28698 HIGH 8.6 2026-07-23 Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the under…
CVE-2026-65694 HIGH 7.5 2026-07-23 Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by …
CVE-2026-65604 HIGH 8.2 2026-07-23 Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body e…
CVE-2026-63313 HIGH Patched 7.7 2026-07-23 9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controlled url parameter and pa…
CVE-2026-16765 HIGH 7.3 2026-07-23 A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unknown functionality of the file /OnlineClassroom/loginlinkadmin.php. Exec…
CVE-2024-58355 HIGH Patched 8.9 2026-07-23 Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking view (e.g., https://app.cal.com/booking/<id>) rende&hellip;
CVE-2024-58353 HIGH Patched 8.9 2026-07-23 Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly accessible single booking view (e.g., /booking/<id>). &hellip;
CVE-2026-50039 HIGH 7.5 2026-07-23 The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corruption via a Read Request.
CVE-2026-50032 HIGH 7.5 2026-07-23 A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a WriteRequest with an e&hellip;
CVE-2026-49035 HIGH 8.1 2026-07-23 The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabl&hellip;
CVE-2026-16796 HIGH Patched 7.3 2026-07-23 Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to&hellip;
CVE-2026-16002 HIGH 8.2 2026-07-23 The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service.
CVE-2026-15968 HIGH Patched 7.1 2026-07-23 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before &hellip;
CVE-2026-15967 HIGH Patched 7.5 2026-07-23 Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
CVE-2026-15966 HIGH Patched 7.5 2026-07-23 Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.&hellip;
CVE-2026-10697 HIGH Patched 7.5 2026-07-23 Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
CVE-2026-65706 HIGH 7.8 2026-07-23 FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a c&hellip;
CVE-2026-65705 HIGH 7.8 2026-07-23 FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a &hellip;
CVE-2026-65704 HIGH 7.8 2026-07-23 FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -s&hellip;
CVE-2026-65703 HIGH 7.8 2026-07-23 FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying &hellip;
CVE-2026-60122 HIGH 7.8 2026-07-23 gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to &hellip;
CVE-2026-25800 HIGH 7.5 2026-07-23 Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and prior to version 0.11.15, the `Assembler` component&hellip;
CVE-2026-15212 HIGH 8.8 2026-07-23 The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_req&hellip;
CVE-2026-63765 HIGH Patched 8.2 2026-07-23 Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStor&hellip;