Export limit exceeded: 372122 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372122 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-17732 | 1 Google | 1 Chrome | 2026-07-30 | 3.1 Low |
| Inappropriate implementation in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-11897 | 1 Ibm | 1 Websphere Application Server Liberty | 2026-07-30 | 7.5 High |
| IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. | ||||
| CVE-2026-17720 | 1 Google | 1 Chrome | 2026-07-30 | 3.1 Low |
| Insufficient policy enforcement in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-17715 | 1 Google | 1 Chrome | 2026-07-30 | 3.1 Low |
| Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-11885 | 1 Ibm | 1 Powervm Hypervisor | 2026-07-30 | 8.4 High |
| IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A carefully crafted OS hypervisor call can cause the PowerVM hypervisor to crash or compromise OS memory integrity. | ||||
| CVE-2026-17702 | 1 Google | 1 Chrome | 2026-07-30 | 3.1 Low |
| Inappropriate implementation in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-65947 | 1 Balbooa.com | 1 Gridbox Extension For Joomla | 2026-07-30 | 7.3 High |
| Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2 | ||||
| CVE-2026-66488 | 1 Balbooa.com | 1 Gridbox Extension For Joomla | 2026-07-30 | 5.3 Medium |
| Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2 | ||||
| CVE-2026-12942 | 1 Ibm | 1 Langflow Oss | 2026-07-30 | 7.5 High |
| IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system. | ||||
| CVE-2026-6879 | 1 Python | 1 Cpython | 2026-07-30 | N/A |
| `Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end of the sibling list, such as with `[last()]` or `[last()-N]`; `.//item[1]` short-circuits after the first match. | ||||
| CVE-2026-57862 | 1 Kanboard | 1 Kanboard | 2026-07-30 | 8.5 High |
| Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplying hexadecimal IP address notation in user-controlled URLs. Attackers can submit hexadecimal-encoded internal IP addresses through the web link creation feature, causing cURL to resolve and connect to internal network resources such as cloud instance metadata services, localhost services, and RFC1918 addresses while the isPrivateURL() filter in app/Core/Http/Client.php incorrectly treats the input as safe due to FILTER_VALIDATE_IP rejecting non-dotted-decimal notation. | ||||
| CVE-2026-10535 | 1 Ibm | 1 Db2 | 2026-07-30 | 8.4 High |
| IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc. | ||||
| CVE-2026-28811 | 1 Apache | 1 Jspwiki | 2026-07-30 | N/A |
| Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this issue. | ||||
| CVE-2026-63358 | 1 Filegator | 1 Filegator | 2026-07-30 | 7.3 High |
| FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' function through 'octdec()' conversion, with no validation. This allows an authenticated user with 'chmod' permission to upgrade their privileges to root. | ||||
| CVE-2026-65058 | 1 Trezor | 3 Safe 3, Safe 5, Safe 7 | 2026-07-30 | 5.3 Medium |
| Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip1559 flow. For contract interactions, the device confirms only the initial calldata chunk while the signature commits to the full streamed calldata. An attacker could present calldata to a victim then supply a different tail that changes the signed transaction. Fixed in 70c9b0c. | ||||
| CVE-2026-67345 | 1 Dromara | 1 Maxkey | 2026-07-30 | 8.1 High |
| MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in DefaultRedirectResolver.hostMatches() that allows remote attackers to hijack OAuth 2.0 authorization codes by supplying a crafted redirect_uri whose hostname suffix matches a registered URI without proper dot-boundary anchoring. Attackers who control a domain ending with the registered redirect URI hostname can social-engineer victims into clicking a crafted authorization URL, causing the authorization code to be issued to the attacker-controlled URI and exchanged for an access token granting access to the victim's identity. | ||||
| CVE-2026-11383 | 1 Ibm | 1 Tivoli System Automation Application Manager | 2026-07-30 | 5.4 Medium |
| IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scripting in the Administrative Console. | ||||
| CVE-2026-14519 | 1 Ibm | 1 App Connect Enterprise | 2026-07-30 | 7.5 High |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a path traversal vulnerability. | ||||
| CVE-2026-13395 | 2 Bookly, Wordpress | 2 Bookly, Wordpress | 2026-07-30 | 8.6 High |
| The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data such as password hashes from the database. | ||||
| CVE-2026-24232 | 1 Nvidia | 1 Transformers4rec | 2026-07-30 | 4.3 Medium |
| NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | ||||