Total CVEs

150,976

Critical Severity

5,036

High Severity

17,677

Last 7 Days

2,114
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,681 - 2,700 of 47,381 CVEs
CVE-2026-46737 MEDIUM - 6.7

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

Vendor: Dell
Product: PowerProtect Data Manager
Published: Jul 22, 2026
Source: NVD
CVE-2026-44276 MEDIUM - 6.0

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the REST API. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

Vendor: Dell
Product: PowerProtect Data Manager
Published: Jul 22, 2026
Source: NVD
CVE-2026-40714 HIGH - 7.2

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

Vendor: Dell
Product: PowerProtect Data Manager
Published: Jul 22, 2026
Source: NVD
CVE-2026-40712 CRITICAL - 9.1

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

Vendor: Dell
Product: PowerProtect Data Manager
Published: Jul 22, 2026
Source: NVD
CVE-2026-16607 HIGH - 7.8

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for local privilege escalation to root of an already authenticated user on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and cove...

Vendor: Fujitsu
Product: Linux openFT, Oracle Solaris openFT
Published: Jul 22, 2026
Source: NVD
CVE-2026-16606 CRITICAL - 9.8

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE beyo...

Vendor: Fujitsu
Product: Linux openFT, Oracle Solaris openFT
Published: Jul 22, 2026
Source: NVD
CVE-2026-16552 MEDIUM - 6.3

A flaw was found in systemd-tmpfiles. When processing a tmpfiles.d configuration entry that writes to a file, systemd-tmpfiles can follow a symbolic link placed by an unprivileged local user, and an existing safety check does not detect this specific case because it always treats transitions away fr...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: Jul 22, 2026
Source: NVD
CVE-2026-48029 HIGH - 7.1

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.

Vendor: strukturag
Product: libheif
Published: Jul 22, 2026
Source: NVD
CVE-2026-2395 CRITICAL - 9.8

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection. This issue affects No Code Platform: from 4.3.1.0 through 20260722. NOTE: The vendor was contacted early a...

Published: Jul 22, 2026
Source: NVD
CVE-2026-14985 HIGH - 7.8

The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper privilege delegation and insufficient input validation in a maintenance script.

Vendor: Analog Way
Product: Picturall Quad Compact Mark II
Published: Jul 22, 2026
Source: NVD
CVE-2026-13321 HIGH - 8.6

The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.2...

Vendor: ISC
Product: BIND 9
Published: Jul 22, 2026
Source: NVD
CVE-2026-13204 HIGH - 7.5

If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20...

Vendor: ISC
Product: BIND 9
Published: Jul 22, 2026
Source: NVD
CVE-2026-12617 HIGH - 7.5

The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds positively to the A query...

Vendor: ISC
Product: BIND 9
Published: Jul 22, 2026
Source: NVD
CVE-2026-11721 HIGH - 7.5

It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoni...

Vendor: ISC
Product: BIND 9
Published: Jul 22, 2026
Source: NVD
CVE-2026-11622 HIGH - 7.5

A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limi...

Vendor: ISC
Product: BIND 9
Published: Jul 22, 2026
Source: NVD
CVE-2026-11605 HIGH - 7.5

The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes the validator to waste...

Vendor: ISC
Product: BIND 9
Published: Jul 22, 2026
Source: NVD
CVE-2026-11331 HIGH - 7.5

An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of t...

Vendor: ISC
Product: BIND 9
Published: Jul 22, 2026
Source: NVD
CVE-2026-10822 MEDIUM - 6.5

If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDNS algorithm (253), and in the algorithm identifier...

Vendor: ISC
Product: BIND 9
Published: Jul 22, 2026
Source: NVD
CVE-2026-10723 MEDIUM - 6.8

BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24...

Vendor: ISC
Product: BIND 9
Published: Jul 22, 2026
Source: NVD
CVE-2026-62145 HIGH - 7.5

A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.

Vendor: checkpoint
Product: Quantum Security Gateway, Quantum Security Management
Published: Jul 22, 2026
Source: NVD