Total CVEs

149,967

Critical Severity

4,910

High Severity

17,396

Last 7 Days

1,778
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 521 - 540 of 46,372 CVEs
CVE-2026-51303 CRITICAL - 9.8

A use-after-free (UAF) vulnerability was discovered in the core parsing component of SQLite 3.41. The flaw occurs because the program frees an ExprList object via sqlite3ExprListDelete and then subsequently accesses the dangling pointer of the released object. A remote adversary can supply specially...

Published: Jul 27, 2026
Source: NVD
CVE-2026-51302 CRITICAL - 9.8

SQLite 3.41 has a use-after-free vulnerability exists in the expression evaluation logic. The sqlite3ReleaseTempReg function improperly releases temporary register resources, and the subsequent exprComputeOperands function continues to access the already freed register memory. By supplying a malicio...

Published: Jul 27, 2026
Source: NVD
CVE-2026-51300 CRITICAL - 9.1

A use-after-free vulnerability exists in the expression parsing and memory management logic of SQLite 3.41. After invoking sqlite3ExprDelete to release an expression object, the program still retains the dangling pointer and subsequently accesses member fields of the already freed memory. By constru...

Published: Jul 27, 2026
Source: NVD
CVE-2026-51298 MEDIUM - 6.2

sqlite 3.41 is vulnerable to use after free in the JSON extraction function. After releasing JsonParse object memory via jsonParseFree(), the program still accesses internal member of the freed pointer, which can cause service crash and denial of service.

Published: Jul 27, 2026
Source: NVD
CVE-2026-51297 HIGH - 8.8

sqlite 3.41 has a use-after-free vulnerability in the JSON parsing logic. Remote adversaries can craft malicious JSON payload to trigger memory free followed by illegal memory access, which may lead to arbitrary code execution, sensitive information leakage and service denial.

Published: Jul 27, 2026
Source: NVD
CVE-2026-51296 HIGH - 7.5

SQLite 3.41 has a use-after-free vulnerability in jsonRemoveFunc of SQLite JSON module. The parsed JSON object is freed at line 3555, while line 3575 still calls jsonLookupStep with the released pointer. Remote attackers can exploit this flaw to crash the service and leak heap memory information.

Published: Jul 27, 2026
Source: NVD

Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module) allows writing files outside the intended extraction directory via a crafted zip archive. zip:unzip/1,2 and zip:extract/1,2 validate entry paths using zip:check_dir_level/2, which tracks directory depth as a running integer cou...

Vendor: Erlang
Product: OTP
Published: Jul 27, 2026
Source: NVD

Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to permanently terminate the Erlang Port Mapper Daemon (epmd) via connection slot exhaustion. The do_accept function in erts/epmd/src/epmd_srv.c calls epmd_cleanup_exit() wh...

Vendor: Erlang
Product: OTP
Published: Jul 27, 2026
Source: NVD

HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read.

Vendor: The HDF Group
Product: HDF5
Published: Jul 27, 2026
Source: NVD

A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double free.

Vendor: The HDF Group
Product: HDF5
Published: Jul 27, 2026
Source: NVD

Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index declares a num_messages count exceeding list_max, triggering out-of-bounds heap ...

Vendor: The HDF Group
Product: HDF5
Published: Jul 27, 2026
Source: NVD
CVE-2026-17530 MEDIUM - 6.3

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/core/astr_agent_tool_exec.py of the component Subagent. The manipulation results in incorrect authorization. The attack may be la...

Vendor: AstrBotDevs
Product: AstrBot
Published: Jul 27, 2026
Source: NVD
CVE-2026-17529 MEDIUM - 6.3

A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The manipulation of the argument req.func_tool leads to incorrect authorization. The attack may be initiated remotely. The exploit is publicly available an...

Vendor: AstrBotDevs
Product: AstrBot
Published: Jul 27, 2026
Source: NVD
CVE-2026-16812 CRITICAL - 10.0

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by ...

Vendor: Arista Networks
Product: VeloCloud Orchestrator On-Prem
Published: Jul 27, 2026
Source: NVD
CVE-2025-50455 CRITICAL - 9.1

SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passed to the order_by method of the CodeIgniter Query Builder, enabling attackers to perform time-base...

Published: Jul 27, 2026
Source: NVD
CVE-2026-66477 MEDIUM - 5.3

Unauthenticated Broken Access Control in Gillion <= 4.13 versions.

Vendor: Shufflehound
Product: Gillion
Published: Jul 27, 2026
Source: NVD
CVE-2026-66476 MEDIUM - 4.9

Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.

Vendor: Syed Balkhi
Product: Easy Digital Downloads
Published: Jul 27, 2026
Source: NVD
CVE-2026-66475 MEDIUM - 5.9

Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5 versions.

Vendor: acowebs
Product: Checkout Field Editor for WooCommerce &#8211; Checkout Manager
Published: Jul 27, 2026
Source: NVD
CVE-2026-66474 MEDIUM - 4.3

Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code โ€“ HT Script <= 1.1.8 versions.

Vendor: HT Plugins
Product: Insert Headers and Footers Code โ€“ HT Script
Published: Jul 27, 2026
Source: NVD
CVE-2026-66448 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.

Vendor: WP Chill
Product: Gallery PhotoBlocks
Published: Jul 27, 2026
Source: NVD