Total CVEs

150,230

Critical Severity

4,940

High Severity

17,474

Last 7 Days

1,818
Quick preset (or use dates below)
Clear Filters
Showing 1,261 - 1,280 of 150,230 CVEs
CVE-2026-66040 HIGH - 8.8

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD ...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 24, 2026
Source: NVD
CVE-2026-66039 HIGH - 8.8

FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_pac...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 24, 2026
Source: NVD
CVE-2026-66038 MEDIUM - 6.5

FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() functi...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 24, 2026
Source: NVD
CVE-2026-66037 MEDIUM - 6.5

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_ob...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 24, 2026
Source: NVD
CVE-2026-66036 HIGH - 8.8

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -re...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 24, 2026
Source: NVD
CVE-2026-62835 CRITICAL - 9.3

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: azure_portal
Published: Jul 24, 2026
Source: NVD
CVE-2026-57531 MEDIUM - 5.4

Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers to execute arbitrary JavaScript in the host application's origin by causing a victim to paste attacker-controlled content. The parseDOM.getAttrs h...

Vendor: Milkdown
Product: milkdown
Published: Jul 24, 2026
Source: NVD
CVE-2026-57530 MEDIUM - 5.4

Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary JavaScript in the browser context of any user who opens the document or clicks a rend...

Vendor: Milkdown
Product: milkdown
Published: Jul 24, 2026
Source: NVD
CVE-2026-54342 HIGH - 8.1

In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnektor, IDP), this allows direct read and modification o...

Vendor: med-united
Product: epa4all
Published: Jul 24, 2026
Source: NVD
CVE-2026-48021 CRITICAL - 9.1

In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traffic (patient consent decisions, medication data, docum...

Vendor: med-united
Product: epa4all
Published: Jul 24, 2026
Source: NVD
CVE-2026-17107 HIGH - 8.5

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke Servi...

Vendor: Red Hat
Product: Multicluster Engine for Kubernetes
Published: Jul 24, 2026
Source: NVD
CVE-2026-66035 HIGH - 7.5

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-the...

Vendor: libssh2
Product: libssh2
Published: Jul 24, 2026
Source: NVD
CVE-2026-66034 HIGH - 7.5

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version ...

Vendor: libssh2
Product: libssh2
Published: Jul 24, 2026
Source: NVD
CVE-2026-66033 HIGH - 7.5

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit...

Vendor: libssh2
Product: libssh2
Published: Jul 24, 2026
Source: NVD
CVE-2026-66032 HIGH - 8.8

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS conta...

Vendor: libssh2
Product: libssh2
Published: Jul 24, 2026
Source: NVD
CVE-2026-65711 HIGH - 7.2

sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands as the web server process user by setting a malicious backup path and triggering a backup. The FileBackupService builds a tar shell command via string ...

Vendor: nuxsmin
Product: sysPass
Published: Jul 24, 2026
Source: NVD
CVE-2026-65710 HIGH - 7.1

sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag to trigger unauthorized decryption and persistent storage of any vault account's password by exploiting the absence of AccountAcl checks in the p...

Vendor: nuxsmin
Product: sysPass
Published: Jul 24, 2026
Source: NVD
CVE-2026-65709 HIGH - 8.3

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account access control. Attackers can invoke Accoun...

Vendor: nuxsmin
Product: sysPass
Published: Jul 24, 2026
Source: NVD
CVE-2026-65708 HIGH - 8.1

sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing authorization checks in AccountFileController. Attacker...

Vendor: nuxsmin
Product: sysPass
Published: Jul 24, 2026
Source: NVD
CVE-2026-65707 MEDIUM - 6.5

Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract arbitrary database contents by submitting unsanitized POST parameters to the adjustAccount endpoint. The adjustAccount method in UserLogic.php concatenates the money, integral, growt...

Vendor: likeadmin-likeshop
Product: likeshop
Published: Jul 24, 2026
Source: NVD