Total CVEs

150,703

Critical Severity

4,956

High Severity

17,517

Last 7 Days

2,022
Quick preset (or use dates below)
Clear Filters
Showing 1,741 - 1,760 of 150,703 CVEs
CVE-2026-57530 MEDIUM - 5.4

Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary JavaScript in the browser context of any user who opens the document or clicks a rend...

Vendor: Milkdown
Product: milkdown
Published: Jul 24, 2026
Source: NVD
CVE-2026-54342 HIGH - 8.1

In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnektor, IDP), this allows direct read and modification o...

Vendor: med-united
Product: epa4all
Published: Jul 24, 2026
Source: NVD
CVE-2026-48021 CRITICAL - 9.1

In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traffic (patient consent decisions, medication data, docum...

Vendor: med-united
Product: epa4all
Published: Jul 24, 2026
Source: NVD
CVE-2026-17107 HIGH - 8.5

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke Servi...

Vendor: Red Hat
Product: Multicluster Engine for Kubernetes
Published: Jul 24, 2026
Source: NVD
CVE-2026-66035 HIGH - 7.5

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-the...

Vendor: libssh2
Product: libssh2
Published: Jul 24, 2026
Source: NVD
CVE-2026-66034 HIGH - 7.5

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version ...

Vendor: libssh2
Product: libssh2
Published: Jul 24, 2026
Source: NVD
CVE-2026-66033 HIGH - 7.5

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit...

Vendor: libssh2
Product: libssh2
Published: Jul 24, 2026
Source: NVD
CVE-2026-66032 HIGH - 8.8

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS conta...

Vendor: libssh2
Product: libssh2
Published: Jul 24, 2026
Source: NVD
CVE-2026-65711 HIGH - 7.2

sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands as the web server process user by setting a malicious backup path and triggering a backup. The FileBackupService builds a tar shell command via string ...

Vendor: nuxsmin
Product: sysPass
Published: Jul 24, 2026
Source: NVD
CVE-2026-65710 HIGH - 7.1

sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag to trigger unauthorized decryption and persistent storage of any vault account's password by exploiting the absence of AccountAcl checks in the p...

Vendor: nuxsmin
Product: sysPass
Published: Jul 24, 2026
Source: NVD
CVE-2026-65709 HIGH - 8.3

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account access control. Attackers can invoke Accoun...

Vendor: nuxsmin
Product: sysPass
Published: Jul 24, 2026
Source: NVD
CVE-2026-65708 HIGH - 8.1

sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing authorization checks in AccountFileController. Attacker...

Vendor: nuxsmin
Product: sysPass
Published: Jul 24, 2026
Source: NVD
CVE-2026-65707 MEDIUM - 6.5

Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract arbitrary database contents by submitting unsanitized POST parameters to the adjustAccount endpoint. The adjustAccount method in UserLogic.php concatenates the money, integral, growt...

Vendor: likeadmin-likeshop
Product: likeshop
Published: Jul 24, 2026
Source: NVD

Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via CPU exhaustion during WebSocket fragment reassembly. The size guard 'Elixir.Bandit.WebSocket.Connection':oversize_message?/2 called from handle_frame/3 in lib/bandit/webs...

Vendor: mtrudel
Product: bandit
Published: Jul 24, 2026
Source: NVD
CVE-2026-59714 HIGH - 7.1

Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)

Vendor: pip
Product: open-webui
Published: Jul 24, 2026
Source: GitHub
CVE-2026-62946 MEDIUM - 5.1

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. This issue has been fixed in...

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: Jul 24, 2026
Source: GitHub
CVE-2026-62363 MEDIUM - 5.0

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has been fixed in version 7.1.2-27.

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: Jul 24, 2026
Source: GitHub
CVE-2026-62343 MEDIUM - 4.7

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel. This issue h...

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: Jul 24, 2026
Source: GitHub
CVE-2026-61632 MEDIUM - 5.3

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

Vendor: pip
Product: pymdown-extensions
Published: Jul 24, 2026
Source: GitHub
CVE-2026-66027 HIGH - 8.3

Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read pending prompt queues of ...

Vendor: kortix-ai
Product: suna
Published: Jul 24, 2026
Source: NVD