Total CVEs

149,967

Critical Severity

4,910

High Severity

17,396

Last 7 Days

1,778
Quick preset (or use dates below)
Clear Filters
Showing 481 - 500 of 149,967 CVEs

Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains an audit log disclosure Vulnerability that could allow an attacker to access audit logs without authentication, potentially resulting in the disclosure of sensitive information. H...

Vendor: Honeywell
Product: S35 Series 3M/5M/8M/PinHole Cameras
Published: Jul 27, 2026
Source: NVD

A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-toolbox. The tool takes an unvalidated pageURL parameter from the client and issues an HTTP GET request to it using an authenticated client. The under...

Vendor: Google
Product: MCP Toolbox for Databases (googleapis/mcp-toolbox)
Published: Jul 27, 2026
Source: NVD
CVE-2026-12383 HIGH - 7.5

A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access controls (permission_classes=[AllowAny], authentication_classes=[]) and relies solely on the Subject HTTP header value for mTLS authentication without verifying that the header originated...

Vendor: Red Hat
Product: Red Hat Ansible Automation Platform 2
Published: Jul 27, 2026
Source: NVD

In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target/slave mode, the rx_full interrupt handler gates the write_requested() callback on dw->state != CMD_SEND, and dw->state is only reset to READY on a STOP interrupt. The START_DET interrupt, whose handler in i2c_dw_s...

Vendor: zephyrproject
Product: zephyr
Published: Jul 27, 2026
Source: NVD
CVE-2026-10682 MEDIUM - 6.6

The userspace verifier z_vrfy_log_filter_set() for the log_filter_set syscall in subsys/logging/log_mgmt.c performed a signed comparison against the int16_t src_id parameter: src_id < (int16_t)log_src_cnt_get(domain_id). Any negative value for src_id (e.g. -1) trivially satisfied this check and w...

Vendor: zephyrproject
Product: zephyr
Published: Jul 27, 2026
Source: NVD
CVE-2026-66030 MEDIUM - 5.4

Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Create New Ticket page. Attackers can craft and store...

Vendor: Creativeitem
Product: Ekushey Project Manager CRM
Published: Jul 27, 2026
Source: NVD
CVE-2026-66029 MEDIUM - 5.4

Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the client Name field on the Edit Profile page without sanitization. Attackers can c...

Vendor: Creativeitem
Product: Ekushey Project Manager CRM
Published: Jul 27, 2026
Source: NVD
CVE-2026-66028 MEDIUM - 6.7

Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers can exploit the lack of email field uniqueness enforcement to c...

Vendor: Creativeitem
Product: Ekushey Project Manager CRM
Published: Jul 27, 2026
Source: NVD

Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a pay...

Vendor: Roskus
Product: Prospero Flow CRM
Published: Jul 27, 2026
Source: NVD

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifies an address by matching it against a table of known IPv6 speci...

Vendor: beaugunderson
Product: ip-address
Published: Jul 27, 2026
Source: NVD
CVE-2026-51235 HIGH - 8.8

LibRaw 0.21 is vulnerable to Buffer Overflow in the stretch() function (src/libraw_cxx.cpp) and fuji_rotate() function (src/decoders/fuji.cpp).

Published: Jul 27, 2026
Source: NVD
CVE-2026-48052 MEDIUM - 5.4

Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who is a member of any organization can delete or rename tags belonging to a different organization, given the target tag's ID. The route handler verifies the caller's members...

Vendor: papra-hq
Product: papra
Published: Jul 27, 2026
Source: NVD
CVE-2026-17570 MEDIUM - 4.3

Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests. This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions Server 202...

Vendor: Devolutions
Product: Server
Published: Jul 27, 2026
Source: NVD
CVE-2026-17569 MEDIUM - 4.3

Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint. This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions...

Vendor: Devolutions
Product: Server
Published: Jul 27, 2026
Source: NVD
CVE-2026-17568 HIGH - 8.8

Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request. This issue affects : * Devolutions ...

Vendor: Devolutions
Product: Server
Published: Jul 27, 2026
Source: NVD
CVE-2026-17552 CRITICAL - 9.1

Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call. When the rewrite base is a plain string, the REQUEST_URI is appended to it, with no check that the path starts with a forward slash ('/'). When the rewri...

Vendor: RRWO
Product: Plack::App::Prerender
Published: Jul 27, 2026
Source: NVD
CVE-2026-66731 HIGH - 7.5

facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that allows unauthenticated remote attackers to crash the server by sending a negative chunk size value. Attackers can send a single POST request with a Transfer-Encoding: chunked...

Vendor: boazsegev
Product: facil.io
Published: Jul 27, 2026
Source: NVD
CVE-2026-66730 HIGH - 7.5

facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unauthenticated remote attacker to permanently freeze worker processes at 100% CPU by sending a multipart/form-data request with a partial closing boundary. The missing progress guard ...

Vendor: boazsegev
Product: facil.io
Published: Jul 27, 2026
Source: NVD
CVE-2026-66729 HIGH - 7.5

facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauthenticated remote attackers to crash the server process by sending a crafted Content-Disposition header with an empty field name. Attackers can trigger a uint32_t wraparound in...

Vendor: boazsegev
Product: facil.io
Published: Jul 27, 2026
Source: NVD
CVE-2026-66391 MEDIUM - 6.5

Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Wicket
Published: Jul 27, 2026
Source: NVD