Total CVEs

149,881

Critical Severity

4,890

High Severity

17,337

Last 7 Days

2,970
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 181 - 200 of 46,286 CVEs
CVE-2026-51564 MEDIUM - 4.9

An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external URLs via a crafted request.

Published: Jul 27, 2026
Source: NVD
CVE-2026-51078 HIGH - 7.5

An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the str parameter of the file_manage_control.php component

Published: Jul 27, 2026
Source: NVD
CVE-2026-51077 HIGH - 7.5

SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the sqlquery parameter of the sys_sql_query.php component

Published: Jul 27, 2026
Source: NVD
CVE-2021-32088 CRITICAL - 9.8

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.

Published: Jul 27, 2026
Source: NVD

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the FTP service interf...

Published: Jul 27, 2026
Source: NVD
CVE-2021-32086 CRITICAL - 9.8

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access to the MySQL server or a backup files can decrypt t...

Published: Jul 27, 2026
Source: NVD
CVE-2021-32085 HIGH - 8.8

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a password of box747, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the My...

Published: Jul 27, 2026
Source: NVD
CVE-2021-32084 CRITICAL - 9.8

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the appliance can still be accessed via the API, lead...

Published: Jul 27, 2026
Source: NVD

Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Values associated with link-like properties, such as url, uri, href, link, website, or homepage, were rendered as hyperlinks without validating their URL scheme. An attacker able to supply or influence no...

Vendor: pivotick
Product: pivotick
Published: Jul 27, 2026
Source: NVD

A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the serialized capture tree directly into an inline JavaScript block using the Jinja safe filter. Because the tree data can contain values derived from captured and potentially attac...

Vendor: lookyloo
Product: lookyloo
Published: Jul 27, 2026
Source: NVD
CVE-2026-64783 HIGH - 8.8

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Vendor: Apple
Product: Safari, iOS and iPadOS, macOS, visionOS, watchOS
Published: Jul 27, 2026
Source: NVD
CVE-2026-64776 MEDIUM - 5.5

The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory.

Vendor: Apple
Product: macOS
Published: Jul 27, 2026
Source: NVD
CVE-2026-64775 CRITICAL - 9.8

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

Vendor: Apple
Product: iOS and iPadOS, macOS, tvOS, visionOS, watchOS
Published: Jul 27, 2026
Source: NVD
CVE-2026-64774 CRITICAL - 9.8

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.

Vendor: Apple
Product: iOS and iPadOS, macOS, tvOS, visionOS
Published: Jul 27, 2026
Source: NVD

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.

Vendor: Apple
Product: iOS and iPadOS, macOS, tvOS, visionOS
Published: Jul 27, 2026
Source: NVD
CVE-2026-64771 CRITICAL - 9.8

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.

Vendor: Apple
Product: iOS and iPadOS, macOS, tvOS, visionOS
Published: Jul 27, 2026
Source: NVD
CVE-2026-64770 CRITICAL - 9.8

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corrupti...

Vendor: Apple
Product: iOS and iPadOS, macOS, tvOS, visionOS
Published: Jul 27, 2026
Source: NVD
CVE-2026-64769 CRITICAL - 9.8

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corrupti...

Vendor: Apple
Product: iOS and iPadOS, macOS, tvOS, visionOS
Published: Jul 27, 2026
Source: NVD
CVE-2026-64768 HIGH - 8.1

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may cause an unexpected app termination.

Vendor: Apple
Product: iOS and iPadOS, macOS, tvOS, visionOS
Published: Jul 27, 2026
Source: NVD
CVE-2026-64767 CRITICAL - 9.8

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

Vendor: Apple
Product: macOS
Published: Jul 27, 2026
Source: NVD