Total CVEs

149,971

Critical Severity

4,911

High Severity

17,397

Last 7 Days

1,770
Quick preset (or use dates below)
Clear Filters
Showing 681 - 700 of 149,971 CVEs
CVE-2026-57990 HIGH - 7.4

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Published: Jul 26, 2026
Source: NVD
CVE-2026-57989 HIGH - 7.4

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Published: Jul 26, 2026
Source: NVD
CVE-2026-57978 MEDIUM - 5.4

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Published: Jul 26, 2026
Source: NVD
CVE-2026-17497 HIGH - 8.3

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating ...

Vendor: codexu
Product: NoteGen
Published: Jul 26, 2026
Source: NVD
CVE-2026-17496 HIGH - 8.1

NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a mal...

Vendor: codexu
Product: NoteGen
Published: Jul 26, 2026
Source: NVD
CVE-2026-17459 MEDIUM - 4.3

A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. Executing a manipulation can lead to symlink following. It is possible ...

Vendor: perwendel
Product: spark
Published: Jul 26, 2026
Source: NVD
CVE-2026-17458 MEDIUM - 6.3

A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server-side request forgery. It is possible to initiate the attack re...

Vendor: mf-yang
Product: openclaw-cn
Published: Jul 26, 2026
Source: NVD
CVE-2026-17457 MEDIUM - 4.3

A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the component Scheme Handler. Such manipulation of the argument url leads to information disclosure. The attack may ...

Vendor: mf-yang
Product: openclaw-cn
Published: Jul 26, 2026
Source: NVD
CVE-2026-64530 CRITICAL - 9.8

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the defragmentation engine (e.g. act_ct on out-of-order fragments). When that happens the skb is no...

Vendor: Linux
Product: Linux
Published: Jul 26, 2026
Source: NVD
CVE-2024-14040 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS networks, as link failures occur at various points in the network, ECMP weights of the involved nodes are adjusted to compensate. With high fan-out of the involved nodes, and overall hi...

Vendor: Linux
Product: Linux
Published: Jul 26, 2026
Source: NVD
CVE-2026-63720 HIGH - 7.5

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines and a dot-free Python expression. The crafted value is ...

Vendor: koxudaxi
Product: datamodel-code-generator
Published: Jul 26, 2026
Source: NVD
CVE-2026-17434 MEDIUM - 6.3

A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been pub...

Vendor: nanocoai
Product: NanoClaw
Published: Jul 26, 2026
Source: NVD
CVE-2026-17433 MEDIUM - 5.3

A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Performing a manipulation results in improper authorization. The attack needs to be approached locally...

Vendor: nanocoai
Product: NanoClaw
Published: Jul 26, 2026
Source: NVD
CVE-2026-15962 HIGH - 8.8

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The addi...

Vendor: techjewel
Product: Fluent Forms Pro Add On Pack
Published: Jul 26, 2026
Source: NVD
CVE-2026-17432 MEDIUM - 5.0

A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId results in improper ...

Vendor: NousResearch
Product: hermes-agent
Published: Jul 26, 2026
Source: NVD
CVE-2026-10681 MEDIUM - 6.5

In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thread permission index from the global _thread_idx_map[] bitmap without holding lists_lock. On SMP systems, two user-mode threads invoking the k_object_alloc(K_OBJ_THREAD) sysca...

Vendor: zephyrproject
Product: zephyr
Published: Jul 25, 2026
Source: NVD

OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authen...

Vendor: openremote
Product: openremote
Published: Jul 25, 2026
Source: NVD
CVE-2026-66012 CRITICAL - 10.0

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy ac...

Vendor: siyuan-note
Product: siyuan
Published: Jul 25, 2026
Source: NVD

ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources.

Vendor: ImageMagick
Product: ImageMagick
Published: Jul 25, 2026
Source: NVD
CVE-2026-64529 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - remove unused character device and IOCTLs The QAT driver exposes a character device (qat_adf_ctl) with IOCTLs for device configuration, start, stop, status query and enumeration. These IOCTLs are not part of any publ...

Vendor: Linux
Product: Linux
Published: Jul 25, 2026
Source: NVD