Total CVEs

150,976

Critical Severity

5,036

High Severity

17,677

Last 7 Days

2,116
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,661 - 2,680 of 47,381 CVEs
CVE-2026-13055 MEDIUM - 6.5

The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to handle compound wildcard index specifications, triggering an internal consistency check that aborts the server process. The user must be able to run an ag...

Vendor: MongoDB
Product: MongoDB Server
Published: Jul 22, 2026
Source: NVD
CVE-2026-3482 MEDIUM - 5.3

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2,  6.2.1.0 through 6.2.1.1_2, and  6.2.2.0 through 6.2.2.0_1 could allow an unauthenticated user to read sensitive information by bypassing authentication through a specially crafted HTTP request.

Published: Jul 22, 2026
Source: NVD

ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.

Vendor: NETAPP
Product: ONTAP 9
Published: Jul 22, 2026
Source: NVD
CVE-2026-16624 CRITICAL - 9.6

Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally video-call passwords, b...

Vendor: Cal.com
Product: Cal.diy
Published: Jul 22, 2026
Source: NVD
CVE-2026-65650 MEDIUM - 4.3

Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.

Vendor: Elgg
Product: Elgg
Published: Jul 22, 2026
Source: NVD
CVE-2026-64835 HIGH - 8.8

FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When A...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 22, 2026
Source: NVD
CVE-2026-64834 HIGH - 7.5

FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when it...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 22, 2026
Source: NVD
CVE-2026-64833 HIGH - 7.1

FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds ...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 22, 2026
Source: NVD
CVE-2026-64832 HIGH - 8.8

FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path free...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 22, 2026
Source: NVD
CVE-2026-16157 HIGH - 7.8

Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Installing the software outside of the Program Files directory, or on a custom path, creates a LocalSystem service running from a directory that any standard local user can write to....

Vendor: Duplicati
Product: Duplicati
Published: Jul 22, 2026
Source: NVD

Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode allows a privileged local attacker to cause a denial of service via mailbox commands containing unverified AXI addresses. The security impact beyond a...

Published: Jul 22, 2026
Source: NVD
CVE-2026-65013 HIGH - 8.8

Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API procedures including project.get, member.remove, and chat...

Vendor: onlook
Product: repo
Published: Jul 22, 2026
Source: NVD
CVE-2026-65012 MEDIUM - 5.3

InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_folder endpoint that accepts attacker-controlled scan_path parameters. Unauthenticated attackers can recursively enumerate arbitrary server filesystem directories and use HTTP respon...

Vendor: invoke-ai
Product: InvokeAI
Published: Jul 22, 2026
Source: NVD
CVE-2026-65011 MEDIUM - 4.3

Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint that allows authenticated users to clone any event definition. Attackers with the low-privilege eventdefinitions:create capability can read private e...

Vendor: Graylog2
Product: graylog2-server
Published: Jul 22, 2026
Source: NVD
CVE-2026-64831 HIGH - 8.8

FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameter...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 22, 2026
Source: NVD
CVE-2026-64830 HIGH - 8.8

FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpe...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 22, 2026
Source: NVD
CVE-2026-16615 MEDIUM - 6.8

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-e...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10
Published: Jul 22, 2026
Source: NVD
CVE-2026-64828 MEDIUM - 6.1

Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary HTML and JavaScript through the order notes field without sanitization. Attackers can craft malicious payloads in customer order placement that execute in ...

Vendor: Froiden
Product: TableTrack
Published: Jul 22, 2026
Source: NVD
CVE-2026-49499 HIGH - 8.8

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

Vendor: Dell
Product: PowerProtect Data Manager
Published: Jul 22, 2026
Source: NVD
CVE-2026-46738 CRITICAL - 9.1

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

Vendor: Dell
Product: PowerProtect Data Manager
Published: Jul 22, 2026
Source: NVD