Total CVEs

150,735

Critical Severity

4,960

High Severity

17,566

Last 7 Days

2,034
Quick preset (or use dates below)
Clear Filters
Showing 1,781 - 1,800 of 150,735 CVEs
CVE-2026-65711 HIGH - 7.2

sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands as the web server process user by setting a malicious backup path and triggering a backup. The FileBackupService builds a tar shell command via string ...

Vendor: nuxsmin
Product: sysPass
Published: Jul 24, 2026
Source: NVD
CVE-2026-65710 HIGH - 7.1

sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag to trigger unauthorized decryption and persistent storage of any vault account's password by exploiting the absence of AccountAcl checks in the p...

Vendor: nuxsmin
Product: sysPass
Published: Jul 24, 2026
Source: NVD
CVE-2026-65709 HIGH - 8.3

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account access control. Attackers can invoke Accoun...

Vendor: nuxsmin
Product: sysPass
Published: Jul 24, 2026
Source: NVD
CVE-2026-65708 HIGH - 8.1

sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing authorization checks in AccountFileController. Attacker...

Vendor: nuxsmin
Product: sysPass
Published: Jul 24, 2026
Source: NVD
CVE-2026-65707 MEDIUM - 6.5

Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract arbitrary database contents by submitting unsanitized POST parameters to the adjustAccount endpoint. The adjustAccount method in UserLogic.php concatenates the money, integral, growt...

Vendor: likeadmin-likeshop
Product: likeshop
Published: Jul 24, 2026
Source: NVD

Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via CPU exhaustion during WebSocket fragment reassembly. The size guard 'Elixir.Bandit.WebSocket.Connection':oversize_message?/2 called from handle_frame/3 in lib/bandit/webs...

Vendor: mtrudel
Product: bandit
Published: Jul 24, 2026
Source: NVD
CVE-2026-59714 HIGH - 7.1

Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)

Vendor: pip
Product: open-webui
Published: Jul 24, 2026
Source: GitHub
CVE-2026-62946 MEDIUM - 5.1

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. This issue has been fixed in...

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: Jul 24, 2026
Source: GitHub
CVE-2026-62363 MEDIUM - 5.0

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has been fixed in version 7.1.2-27.

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: Jul 24, 2026
Source: GitHub
CVE-2026-62343 MEDIUM - 4.7

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel. This issue h...

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: Jul 24, 2026
Source: GitHub
CVE-2026-61632 MEDIUM - 5.3

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

Vendor: pip
Product: pymdown-extensions
Published: Jul 24, 2026
Source: GitHub
CVE-2026-66027 HIGH - 8.3

Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read pending prompt queues of ...

Vendor: kortix-ai
Product: suna
Published: Jul 24, 2026
Source: NVD
CVE-2026-65693 HIGH - 7.2

Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into mail templates. Attackers can exploit the unsandboxed Twig environment in TwigView::render(), wh...

Vendor: microweber
Product: microweber
Published: Jul 24, 2026
Source: NVD
CVE-2026-64255 HIGH - 8.8

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers Three BA session handlers use ffs(ba_data->sta_mask) - 1 to derive a station ID without checking that sta_mask is non-zero. When sta_mask is zero, ffs() ...

Vendor: Linux
Product: Linux
Published: Jul 24, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR When BAR_PEER_SPAD and BAR_CONFIG share one PCI BAR, the module teardown path ends up calling pci_iounmap() on the same iomem with some offset, which is...

Vendor: Linux
Product: Linux
Published: Jul 24, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: kernel/fork: clear PF_BLOCK_TS in copy_process() PF_BLOCK_TS is only set in blk_time_get_ns() when current->plug is non-NULL, and blk_finish_plug() clears it via __blk_flush_plug() before NULLing the plug pointer. copy_process...

Vendor: Linux
Product: Linux
Published: Jul 24, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: MIPS: DEC: Prevent initial console buffer from landing in XKPHYS In 64-bit configurations calling the initial console output handler from a kernel thread other than the initial one will result in a situation where the stack has be...

Vendor: Linux
Product: Linux
Published: Jul 24, 2026
Source: NVD
CVE-2026-64251 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next() pwrseq_debugfs_seq_next() declares 'next' with __free(put_device), which causes put_device() to be called on the returned pointer when the variable goes out o...

Vendor: Linux
Product: Linux
Published: Jul 24, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: LoongArch: Report dying CPU to RCU in stop_this_cpu() This is a port of MIPS commit 9f3f3bdc6d9dac1 ("MIPS: smp: report dying CPU to RCU in stop_this_cpu()"). smp_send_stop() parks all secondary CPUs in stop_this_cpu(). ...

Vendor: Linux
Product: Linux
Published: Jul 24, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: fpga: region: fix use-after-free in child_regions_with_firmware() Move of_node_put(child_region) after the error print to avoid accessing freed memory when pr_err() references child_region. [ Yilun: Fix the Fixes tag ]

Vendor: Linux
Product: Linux
Published: Jul 24, 2026
Source: NVD