Total CVEs

149,967

Critical Severity

4,910

High Severity

17,396

Last 7 Days

1,778
Quick preset (or use dates below)
Clear Filters
Showing 501 - 520 of 149,967 CVEs
CVE-2026-66390 MEDIUM - 6.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Wicket
Published: Jul 27, 2026
Source: NVD
CVE-2026-63077 CRITICAL - 9.8

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Vendor: JetBrains
Product: TeamCity
Published: Jul 27, 2026
Source: NVD
CVE-2026-24252 HIGH - 7.8

NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.

Vendor: NVIDIA
Product: NeMo Framework
Published: Jul 27, 2026
Source: NVD
CVE-2026-17531 MEDIUM - 5.0

A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the component Unsigned Scheduled Callback. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. ...

Vendor: unitedbyai
Product: droidclaw
Published: Jul 27, 2026
Source: NVD
CVE-2026-17192 HIGH - 8.5

A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. This issue was discovered i...

Vendor: Arista Networks
Product: VeloCloud Orchestrator On-Prem
Published: Jul 27, 2026
Source: NVD
CVE-2026-17191 CRITICAL - 9.1

An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outboun...

Vendor: Arista Networks
Product: VeloCloud Orchestrator On-Prem
Published: Jul 27, 2026
Source: NVD
CVE-2023-37465 MEDIUM - 6.5

org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages

Vendor: maven
Product: org.xwiki.contrib:discussions-server
Published: Jul 27, 2026
Source: GitHub
CVE-2026-66399 MEDIUM - 6.5

phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows administrators with only group-management permissions to join privileged groups without verification of required rights. Attackers can add themselves to pre-existing groups holding use...

Vendor: thorsten
Product: phpMyFAQ
Published: Jul 27, 2026
Source: NVD

phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated administrators with CONFIGURATION_EDIT and ATTACHMENT_ADD privileges to write arbitrary PHP files by manipulating the upgrade.lastDownloadedPackage setting. Attackers can upload a...

Vendor: thorsten
Product: phpMyFAQ
Published: Jul 27, 2026
Source: NVD

phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowing authenticated attackers to delete arbitrary files by exploiting insufficient sanitization in Image::delete(). Attackers can delete the database.php configuration file to dis...

Vendor: thorsten
Product: phpMyFAQ
Published: Jul 27, 2026
Source: NVD
CVE-2026-66396 HIGH - 8.4

SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor permissions can inject onload handlers that execute arbitrary cod...

Vendor: siyuan-note
Product: siyuan
Published: Jul 27, 2026
Source: NVD
CVE-2026-66395 CRITICAL - 9.6

SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter that execute with ful...

Vendor: siyuan-note
Product: siyuan
Published: Jul 27, 2026
Source: NVD
CVE-2026-66394 HIGH - 8.7

SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows authenticated attackers to execute scripts by bypassing the HTML parser-based cleaner. Attackers can hide script tags within desc, style, or noscript elements which the HTML parser...

Vendor: siyuan-note
Product: siyuan
Published: Jul 27, 2026
Source: NVD

Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial of service by sending a crafted X.509 certificate chain during the TLS handshake. During RFC 5280 policy processing in public_key:pkix_path_validation...

Vendor: Erlang
Product: OTP
Published: Jul 27, 2026
Source: NVD

Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and potentially achieve remote code execution or a denial-of-service crash) by sending a single text-encoded H.248/Megaco message containing an oversiz...

Vendor: Erlang
Product: OTP
Published: Jul 27, 2026
Source: NVD

The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS or DTLS handshake. In ssl_certificate:handle_incomplete_chain/5, the received chain is passed to ssl_certificate:build_certificate_chain/5, which walks issuer relationships via...

Vendor: Erlang
Product: OTP
Published: Jul 27, 2026
Source: NVD

The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello. The client-side tls_handshake:hello/5 handler validates the negotiated protocol version and the downgrade se...

Vendor: Erlang
Product: OTP
Published: Jul 27, 2026
Source: NVD

Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can supply a crafted Erlang external term format (ETF) binary to binary_to_term/1 to corrupt the BEAM heap pointer and crash the virtual machine. When decoding a LARGE_TUPLE_EXT term,...

Vendor: Erlang
Product: OTP
Published: Jul 27, 2026
Source: NVD

Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modules) allows Forced Integer Overflow, Excessive Allocation. This vulnerability is associated with program files erts/emulator/beam/external.c, emulator/beam/external.c. The BIT_BIN...

Vendor: Erlang
Product: OTP
Published: Jul 27, 2026
Source: NVD
CVE-2026-51304 HIGH - 7.5

sqlite 3.41 has a use-after-free (UAF) vulnerability in the ORDER BY clause parsing routine. The affected code first releases the memory of an ExprList object via sqlite3ExprListDelete(), then attempts to access the nExpr member of the already freed object. This dangling pointer access causes invali...

Published: Jul 27, 2026
Source: NVD