Total CVEs

150,735

Critical Severity

4,960

High Severity

17,566

Last 7 Days

2,012
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,941 - 1,960 of 47,140 CVEs
CVE-2026-11922 MEDIUM - 6.5

A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST /api/v1/login` and self password-change endpoints by rotating the `X-Forwarded-For` header. The rate limiter keys requests by `request.client.host`, which is derived from the `X-F...

Vendor: zenml-io
Product: zenml-io/zenml
Published: Jul 24, 2026
Source: NVD
CVE-2026-11354 MEDIUM - 5.3

The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and redirect th...

Vendor: xnau
Product: Participants Database
Published: Jul 24, 2026
Source: NVD
CVE-2025-9205 MEDIUM - 6.4

The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.0. This is due to insufficient input sanitization and output escaping on user supplied attributes within the map options. This makes it possible for authenticated attackers, with c...

Published: Jul 24, 2026
Source: NVD
CVE-2026-62825 CRITICAL - 10.0

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

Published: Jul 24, 2026
Source: NVD
CVE-2026-58275 CRITICAL - 10.0

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

Published: Jul 24, 2026
Source: NVD
CVE-2026-56191 CRITICAL - 10.0

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

Vendor: microsoft
Product: exchange_online
Published: Jul 24, 2026
Source: NVD
CVE-2026-56167 HIGH - 8.5

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: azure_ai_search
Published: Jul 24, 2026
Source: NVD
CVE-2026-56165 CRITICAL - 9.8

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

Published: Jul 24, 2026
Source: NVD
CVE-2026-56160 CRITICAL - 9.1

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

Published: Jul 24, 2026
Source: NVD
CVE-2026-54120 CRITICAL - 9.9

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

Published: Jul 24, 2026
Source: NVD
CVE-2026-50517 CRITICAL - 9.9

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

Vendor: microsoft
Product: 365_copilot
Published: Jul 24, 2026
Source: NVD
CVE-2026-49159 MEDIUM - 6.5

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

Vendor: microsoft
Product: graph
Published: Jul 24, 2026
Source: NVD
CVE-2026-35425 HIGH - 8.0

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

Published: Jul 24, 2026
Source: NVD
CVE-2026-50044 MEDIUM - 6.8

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin credentials via weak hash or a pass-the-hash attack.

Vendor: Pronetiqs
Product: Panduit Intravue
Published: Jul 23, 2026
Source: NVD
CVE-2026-44955 MEDIUM - 5.3

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could allow for asset discovery by unauthenticated users.

Vendor: Pronetiqs
Product: Panduit Intravue
Published: Jul 23, 2026
Source: NVD
CVE-2026-42933 CRITICAL - 10.0

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.

Vendor: Pronetiqs
Product: Panduit Intravue
Published: Jul 23, 2026
Source: NVD
CVE-2026-40430 HIGH - 7.5

Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API.

Vendor: Pronetiqs
Product: Panduit Intravue
Published: Jul 23, 2026
Source: NVD
CVE-2026-28698 HIGH - 8.6

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem.

Vendor: Pronetiqs
Product: Panduit Intravue
Published: Jul 23, 2026
Source: NVD
CVE-2026-16767 MEDIUM - 6.5

A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file src/ZipFile.php of the component ZIP Handler. Performing a manipulation of the argument entryName results in path traversal. It is possible to initiate the attack remotely. The explo...

Vendor: Ne-Lexa
Product: php-zip
Published: Jul 23, 2026
Source: NVD
CVE-2026-65694 HIGH - 7.5

Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the path query parameter. Attackers can send a single unauthenticated HTTP GET reques...

Vendor: microweber
Product: microweber
Published: Jul 23, 2026
Source: NVD