Total CVEs

150,230

Critical Severity

4,940

High Severity

17,474

Last 7 Days

1,818
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,341 - 1,360 of 46,635 CVEs

ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape

Vendor: pip
Product: onnx
Published: Jul 24, 2026
Source: GitHub
CVE-2026-8789 HIGH - 8.1

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it possible for authenticated a...

Published: Jul 24, 2026
Source: NVD
CVE-2026-8308 MEDIUM - 6.1

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services Website Template allows Reflected XSS. This issue affects Website Template: before v2.

Published: Jul 24, 2026
Source: NVD
CVE-2026-7007 MEDIUM - 4.6

The Zephyr ext2 file system validates the on-disk superblock in ext2_verify_disk_superblock() (subsys/fs/ext2/ext2_impl.c) before completing a mount. The validator checked the magic number, block size, revision and feature flags, but did not verify that the on-disk fields s_blocks_per_group and s_in...

Published: Jul 24, 2026
Source: NVD
CVE-2026-66007 MEDIUM - 6.5

Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadata field is not properly validated before being joined to the dataset directory. Attackers can supply crafted file_name values with directory traversal ...

Vendor: huggingface
Product: datasets
Published: Jul 24, 2026
Source: NVD
CVE-2026-66006 MEDIUM - 5.3

lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint that allows unauthenticated attackers to overwrite operator metadata including email, name, and company after setup completion. Attackers can POST to this endpoint to mod...

Vendor: treeverse
Product: lakeFS
Published: Jul 24, 2026
Source: NVD
CVE-2026-66005 MEDIUM - 6.3

Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-configured trusted hosts with a wildcard that reflects arb...

Vendor: janhq
Product: jan
Published: Jul 24, 2026
Source: NVD
CVE-2026-66004 MEDIUM - 5.3

BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitrary files by injecting traversal sequences in API response include keys. Attackers performing MITM attacks or prompt injection can supply malicious pat...

Vendor: ahujasid
Product: blender-mcp
Published: Jul 24, 2026
Source: NVD
CVE-2026-58630 CRITICAL - 10.0

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

Published: Jul 24, 2026
Source: NVD
CVE-2026-58586 CRITICAL - 9.8

Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has multiple known vulnerabilities, including CVE-2023-4863. Any caller that decod...

Vendor: ZAPAD
Product: Image::WebP
Published: Jul 24, 2026
Source: NVD
CVE-2026-57106 CRITICAL - 10.0

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: purview_data_governance
Published: Jul 24, 2026
Source: NVD
CVE-2026-56163 CRITICAL - 10.0

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: azure_kubernetes_service
Published: Jul 24, 2026
Source: NVD

Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 on LINX-A64 allows an unauthenticated remote attacker to crash `linx_a64.exe` and ultimately reboot the device via a malformed BAC...

Vendor: Loytec
Product: LIP-ME20xC, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD
Published: Jul 24, 2026
Source: NVD

Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to cause persistent denial of service (CPU exhaustion) via a crafted SNMP GETNEXT request wit...

Vendor: Loytec
Product: LIP-ME20xC, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD
Published: Jul 24, 2026
Source: NVD

Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's browser and perform actions with the victim's privileges via a crafted link containing a malicious `pr...

Vendor: Loytec
Product: LWEB-802
Published: Jul 24, 2026
Source: NVD

Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to leak stored management credentials via a crafted link.

Vendor: Loytec
Product: LWEB-802
Published: Jul 24, 2026
Source: NVD

Stack-based Buffer Overflow (CWE-121) in `/usr/bin/ltsudo` `cmd_ipaddr_conflict` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to trigger a SUID-root process abort or potentially elevate privileges via an o...

Vendor: Loytec
Product: LIP-ME20xC, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD
Published: Jul 24, 2026
Source: NVD
CVE-2026-49326 MEDIUM - 6.5

Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest service has 3 steps, open, fetch(possible multiple times), close. The open step will return an id which will be passed back to server for identifying the scanner instances stored ...

Vendor: Apache Software Foundation
Product: Apache HBase
Published: Jul 24, 2026
Source: NVD
CVE-2026-17059 MEDIUM - 6.5

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when listing members of a ...

Vendor: Red Hat
Product: Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Single Sign-On 7
Published: Jul 24, 2026
Source: NVD
CVE-2026-16802 MEDIUM - 6.5

Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected.

Vendor: Devolutions
Product: PowerShell Universal
Published: Jul 24, 2026
Source: NVD