Total CVEs

150,976

Critical Severity

5,036

High Severity

17,677

Last 7 Days

2,116
Quick preset (or use dates below)
Clear Filters
Showing 2,561 - 2,580 of 150,976 CVEs
CVE-2026-63226 MEDIUM - 5.8

Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.

Vendor: Ricoh Company
Product: Ricoh printers and Multifunction Printers (MFPs)
Published: Jul 23, 2026
Source: NVD
CVE-2026-6390 MEDIUM - 6.8

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to...

Published: Jul 23, 2026
Source: NVD
CVE-2026-7120 MEDIUM - 5.3

@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and including 10.1.1 are affected. An unauthenticated attacker can bypass allowedPath restrictions by requesting equivalent non-ca...

Vendor: npm
Product: @fastify/static
Published: Jul 23, 2026
Source: NVD
CVE-2026-15074 HIGH - 7.5

@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This is a bypass of the earlier fix for CVE-2026-6414, which only covered encoded forward slashes. Because the underlying send library normalizes dot segmen...

Vendor: @fastify/static
Product: @fastify/static
Published: Jul 23, 2026
Source: NVD
CVE-2026-21723 MEDIUM - 5.3

The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anon...

Vendor: Grafana
Product: Grafana OSS
Published: Jul 23, 2026
Source: NVD
CVE-2026-16653 MEDIUM - 5.3

A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public Folder Handler. Performing a manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit h...

Vendor: boazsegev
Product: facil.io
Published: Jul 23, 2026
Source: NVD
CVE-2026-16632 HIGH - 7.3

A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the library lib/facil/http/parsers/websocket_parser.h of the component WebSocket Frame Parser. This manipulation of the argument on_message causes improper input validation. The attack ca...

Vendor: boazsegev
Product: facil.io
Published: Jul 23, 2026
Source: NVD
CVE-2026-16631 MEDIUM - 5.3

A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Handler. The manipulation results in os command injection. Attacking locally is a requirement. The exploit is now public and may be ...

Product: publint
Published: Jul 23, 2026
Source: NVD
CVE-2026-61246 HIGH - 8.8

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to c...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-60455 HIGH - 8.8

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to c...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-60439 HIGH - 8.8

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to c...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-60373 HIGH - 8.8

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to c...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-60372 CRITICAL - 9.8

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to ...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-60371 HIGH - 8.0

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with access to the physical com...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-60370 HIGH - 7.5

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-60369 CRITICAL - 9.9

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to c...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-60368 HIGH - 8.8

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to c...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-60367 CRITICAL - 9.8

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to ...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-60366 CRITICAL - 10.0

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to ...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-38766 HIGH - 7.8

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function

Published: Jul 22, 2026
Source: NVD