Search
3,449 CVEs · Medium severity
CVEs (3,449, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 3,449 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-50044 | MEDIUM | 6.8 | 2026-07-23 | Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin credentials via weak hash o… | |
| CVE-2026-44955 | MEDIUM | 5.3 | 2026-07-23 | Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could allow for asset … | |
| CVE-2026-16767 | MEDIUM | 6.5 | 2026-07-23 | A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file src/ZipFile.php of the component ZIP Handler. Performi… | |
| CVE-2026-16764 | MEDIUM | 6.3 | 2026-07-23 | A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. S… | |
| CVE-2026-16763 | MEDIUM | 5.3 | 2026-07-23 | A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js of the component Config… | |
| CVE-2026-50103 | MEDIUM | 6.5 | 2026-07-23 | A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to crash a subscribing application by sending a crafted GO… | |
| CVE-2026-48013 | MEDIUM | Patched | 4.1 | 2026-07-23 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side… |
| CVE-2026-48012 | MEDIUM | 4.3 | 2026-07-23 | Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO entry point at `GET /api/oauth/sso/auth`. When the e… | |
| CVE-2026-12353 | MEDIUM | 5.3 | 2026-07-23 | An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending o… | |
| CVE-2026-65010 | MEDIUM | Patched | 6.6 | 2026-07-23 | Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that allows local attackers to write arbitrary files by pr… |
| CVE-2026-65920 | MEDIUM | Patched | 4.3 | 2026-07-23 | Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitra… |
| CVE-2026-65699 | MEDIUM | 4.2 | 2026-07-23 | AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent ru… | |
| CVE-2026-47769 | MEDIUM | 5.3 | 2026-07-23 | APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Prior to commit 7f19b52280f414f57af2b79a95333d1c8fbeec… | |
| CVE-2026-47755 | MEDIUM | 6.5 | 2026-07-23 | ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can ret… | |
| CVE-2026-65698 | MEDIUM | 5.3 | 2026-07-23 | Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside th… | |
| CVE-2026-65697 | MEDIUM | 6.1 | 2026-07-23 | Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that allows unauthenticated attackers to inject a javasc… | |
| CVE-2026-65696 | MEDIUM | 5.4 | 2026-07-23 | Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, re… | |
| CVE-2026-65695 | MEDIUM | 6.8 | 2026-07-23 | Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filename argument to read ar… | |
| CVE-2026-16768 | MEDIUM | 5.3 | 2026-07-23 | A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to im… | |
| CVE-2026-48539 | MEDIUM | Patched | 5.4 | 2026-07-23 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authenticated attackers to inj… |
| CVE-2026-48538 | MEDIUM | Patched | 5.4 | 2026-07-23 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configuration that allows authenticated attackers to inject ar… |
| CVE-2026-48537 | MEDIUM | Patched | 5.4 | 2026-07-23 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configuration that allows authenticated attackers to inject arb… |
| CVE-2026-48536 | MEDIUM | Patched | 5.4 | 2026-07-23 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated attackers to inject arbi… |
| CVE-2026-48535 | MEDIUM | Patched | 5.4 | 2026-07-23 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configuration that allows authenticated attackers to inject arb… |
| CVE-2026-48534 | MEDIUM | Patched | 5.4 | 2026-07-23 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers to inject arbitrary web … |