Export limit exceeded: 367923 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (367923 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-63770 | 2026-07-20 | 7.5 High | ||
| Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthenticated attackers to bypass brute-force lockout protections by supplying arbitrary values in the X-Forwarded-For request header when the server proxied option is enabled. Attackers can manipulate the leftmost value of the X-Forwarded-For header to make each login attempt appear to originate from a distinct IP address, preventing the per-IP failed-login counter from reaching the lockout threshold and enabling unlimited credential guessing against the authentication endpoint. | ||||
| CVE-2026-35198 | 2026-07-20 | 9 Critical | ||
| HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes when a team owner views the form, leading to complete account takeover through privilege escalation. Version 3.0.0-rc.7 contains a patch for the issue. | ||||
| CVE-2026-41521 | 2026-07-20 | 8.2 High | ||
| xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VNC server can send crafted image dimensions that cause an integer overflow during memory buffer size calculation, resulting in an undersized allocation. Subsequent processing of the incoming image data using the original oversized parameters leads to an out-of-bounds read. An unauthenticated remote attacker could exploit this flaw to disclose sensitive information from the heap memory or cause a denial of service (DoS) via a process crash. This issue has been fixed in version 0.10.6.1. | ||||
| CVE-2026-61425 | 2026-07-20 | N/A | ||
| The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access. | ||||
| CVE-2026-63731 | 2026-07-20 | 7.7 High | ||
| HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to arbitrary internal destinations by supplying a caller-controlled host parameter to the ClickHouse proxy test endpoint with no URL validation or allowlist enforcement. Attackers can exploit the reflected error responses from the endpoint to disclose internal service response bodies, enabling access to internal APIs, container services, and cloud provider metadata endpoints. | ||||
| CVE-2026-46715 | 2026-07-20 | N/A | ||
| Flask-Security-Too allows users to add security features to their Flask applicationa. Version 5.8.0's OAuth reauthentication flow can mark a session as fresh after verifying an OAuth account that belongs to a different user. If an attacker can operate an already-authenticated but stale victim session, they can complete OAuth verification using their own OAuth identity. The victim session is then treated as recently reauthenticated, allowing freshness-protected account actions to proceed. Version 5.8.1 contains a fix for this issue. | ||||
| CVE-2026-64612 | 1 Redhat | 1 Enterprise Linux | 2026-07-20 | 7.5 High |
| A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job. | ||||
| CVE-2026-61424 | 2026-07-20 | N/A | ||
| The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE. | ||||
| CVE-2026-62414 | 2026-07-20 | N/A | ||
| The Joomla extension Page Builder CK does not properly apply access control to frontend page list views. | ||||
| CVE-2026-61900 | 2026-07-20 | N/A | ||
| The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE. | ||||
| CVE-2026-61901 | 2026-07-20 | N/A | ||
| The Joomla extension Hikashop is vulnerable to an open redirect. | ||||
| CVE-2026-6793 | 2026-07-20 | 5.4 Medium | ||
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS. This issue affects Q-smart NexT Poll: before 1.8.7. | ||||
| CVE-2026-51027 | 2026-07-20 | 9.9 Critical | ||
| An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component. | ||||
| CVE-2026-51026 | 2026-07-20 | 6.5 Medium | ||
| Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a crafted request. | ||||
| CVE-2026-26081 | 1 Haproxy | 1 Haproxy | 2026-07-20 | 4.8 Medium |
| HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected. | ||||
| CVE-2026-50162 | 2026-07-20 | 5.3 Medium | ||
| oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a lexical filepath.Rel check for workingDir and does not account for symlink traversal, so when AllowPathTraversalOnWrite=false an attacker-controlled blob title through ocispec.AnnotationTitle such as out/pwn.txt can follow a workingDir symlink out -> /some/outside/dir and cause pushFile() to create /some/outside/dir/pwn.txt outside workingDir. This issue is fixed in version 2.6.1. | ||||
| CVE-2026-26483 | 2026-07-20 | 6.1 Medium | ||
| Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. The application fails to properly sanitize user-supplied input in the content parameter of the /templates endpoint, allowing an attacker to persistently inject malicious JavaScript code that is executed in the browsers of users who access the affected template. | ||||
| CVE-2026-26080 | 1 Haproxy | 1 Haproxy | 2026-07-20 | 3.7 Low |
| HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected. | ||||
| CVE-2026-46420 | 2026-07-20 | 5.6 Medium | ||
| setup-php is a GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and tools. From 2.25.0 prior to 2.37.1, shivammathur/setup-php resolves the PHP version from repository-controlled files such as .php-version, composer.lock through platform-overrides.php, and composer.json through config.platform.php, and insufficiently constrains those values before incorporating them into generated shell or PowerShell setup scripts, allowing command injection on a GitHub Actions runner when workflows such as pull_request_target check out attacker-controlled contents before invoking setup-php. This issue is fixed in version 2.37.1. | ||||
| CVE-2026-60027 | 2026-07-20 | N/A | ||
| The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticated users frontend users are allowed traversal paths and read arbitrary files. Requires a published page with a Form element. | ||||