Total CVEs

150,920

Critical Severity

5,034

High Severity

17,670

Last 7 Days

2,079
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,521 - 2,540 of 47,325 CVEs
CVE-2026-60368 HIGH - 8.8

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to c...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-60367 CRITICAL - 9.8

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to ...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-60366 CRITICAL - 10.0

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to ...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-38766 HIGH - 7.8

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function

Published: Jul 22, 2026
Source: NVD
CVE-2026-38765 HIGH - 7.8

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

Published: Jul 22, 2026
Source: NVD
CVE-2026-38763 MEDIUM - 5.5

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828

Published: Jul 22, 2026
Source: NVD
CVE-2026-16630 MEDIUM - 5.3

A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the file package.json. The manipulation leads to os command injection. An attack has to be approached locally. The exploit has been disclosed publicly and...

Vendor: syncfusion
Product: ej2-javascript-ui-controls
Published: Jul 22, 2026
Source: NVD
CVE-2026-64649 HIGH - 6.5

Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery)...

Vendor: npm
Product: next
Published: Jul 22, 2026
Source: GitHub
CVE-2026-64648 MEDIUM - 5.4

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidential data in the POST&...

Vendor: npm
Product: next
Published: Jul 22, 2026
Source: GitHub
CVE-2026-64647 MEDIUM - 5.4

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidential data in the POST&#...

Vendor: npm
Product: next
Published: Jul 22, 2026
Source: GitHub
CVE-2026-64646 MEDIUM - 5.3

Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge...

Vendor: npm
Product: next
Published: Jul 22, 2026
Source: GitHub
CVE-2026-64645 HIGH - 6.1

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of t...

Vendor: npm
Product: next
Published: Jul 22, 2026
Source: GitHub
CVE-2026-64644 MEDIUM - 5.3

Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If tho...

Vendor: npm
Product: next
Published: Jul 22, 2026
Source: GitHub
CVE-2026-64643 MEDIUM - 5.3

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server Actions (use server) or use cache endpoints can be disclosed bypassing any authentication on the pages where these endpo...

Vendor: npm
Product: next
Published: Jul 22, 2026
Source: GitHub
CVE-2026-64642 HIGH - 8.2

Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales can bypass middleware/proxy based authentication. This issue has ...

Vendor: npm
Product: next
Published: Jul 22, 2026
Source: GitHub
CVE-2026-64641 HIGH - 7.5

Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further reques...

Vendor: npm
Product: next
Published: Jul 22, 2026
Source: GitHub

Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution

Vendor: maven
Product: org.eclipse.jetty:jetty-security
Published: Jul 22, 2026
Source: GitHub

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by Dompdf they can utilize the SVG rendering functionality to leak filesystem information when rendering PDF files using image references within a data-URI encod...

Vendor: composer
Product: dompdf/dompdf
Published: Jul 22, 2026
Source: GitHub

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. An attacker can crash the PHP process by providing a specially crafted HTML document containing a single image with massive dimensions (e.g., 30,000x30,000 ...

Vendor: composer
Product: dompdf/dompdf
Published: Jul 22, 2026
Source: GitHub

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on its declared header dimensions and never bounds width ร— height before the image is converted through GD. A 58-byte BMP whose header declares e.g. 6000ร—6000 is accep...

Vendor: composer
Product: dompdf/dompdf
Published: Jul 22, 2026
Source: GitHub