Total CVEs

150,152

Critical Severity

4,935

High Severity

17,450

Last 7 Days

1,744
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,181 - 1,200 of 46,557 CVEs
CVE-2026-55495 MEDIUM - 4.3

Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account

Vendor: go
Product: github.com/cloudreve/Cloudreve/v4
Published: Jul 24, 2026
Source: GitHub
CVE-2026-66041 HIGH - 8.8

FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 24, 2026
Source: NVD
CVE-2026-66040 HIGH - 8.8

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD ...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 24, 2026
Source: NVD
CVE-2026-66039 HIGH - 8.8

FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_pac...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 24, 2026
Source: NVD
CVE-2026-66038 MEDIUM - 6.5

FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() functi...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 24, 2026
Source: NVD
CVE-2026-66037 MEDIUM - 6.5

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_ob...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 24, 2026
Source: NVD
CVE-2026-66036 HIGH - 8.8

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -re...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 24, 2026
Source: NVD
CVE-2026-62835 CRITICAL - 9.3

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: azure_portal
Published: Jul 24, 2026
Source: NVD
CVE-2026-57531 MEDIUM - 5.4

Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers to execute arbitrary JavaScript in the host application's origin by causing a victim to paste attacker-controlled content. The parseDOM.getAttrs h...

Vendor: Milkdown
Product: milkdown
Published: Jul 24, 2026
Source: NVD
CVE-2026-57530 MEDIUM - 5.4

Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary JavaScript in the browser context of any user who opens the document or clicks a rend...

Vendor: Milkdown
Product: milkdown
Published: Jul 24, 2026
Source: NVD
CVE-2026-54342 HIGH - 8.1

In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnektor, IDP), this allows direct read and modification o...

Vendor: med-united
Product: epa4all
Published: Jul 24, 2026
Source: NVD
CVE-2026-48021 CRITICAL - 9.1

In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traffic (patient consent decisions, medication data, docum...

Vendor: med-united
Product: epa4all
Published: Jul 24, 2026
Source: NVD
CVE-2026-17107 HIGH - 8.5

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke Servi...

Vendor: Red Hat
Product: Multicluster Engine for Kubernetes
Published: Jul 24, 2026
Source: NVD
CVE-2026-66035 HIGH - 7.5

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-the...

Vendor: libssh2
Product: libssh2
Published: Jul 24, 2026
Source: NVD
CVE-2026-66034 HIGH - 7.5

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version ...

Vendor: libssh2
Product: libssh2
Published: Jul 24, 2026
Source: NVD
CVE-2026-66033 HIGH - 7.5

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit...

Vendor: libssh2
Product: libssh2
Published: Jul 24, 2026
Source: NVD
CVE-2026-66032 HIGH - 8.8

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS conta...

Vendor: libssh2
Product: libssh2
Published: Jul 24, 2026
Source: NVD
CVE-2026-65711 HIGH - 7.2

sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands as the web server process user by setting a malicious backup path and triggering a backup. The FileBackupService builds a tar shell command via string ...

Vendor: nuxsmin
Product: sysPass
Published: Jul 24, 2026
Source: NVD
CVE-2026-65710 HIGH - 7.1

sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag to trigger unauthorized decryption and persistent storage of any vault account's password by exploiting the absence of AccountAcl checks in the p...

Vendor: nuxsmin
Product: sysPass
Published: Jul 24, 2026
Source: NVD
CVE-2026-65709 HIGH - 8.3

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account access control. Attackers can invoke Accoun...

Vendor: nuxsmin
Product: sysPass
Published: Jul 24, 2026
Source: NVD