Export limit exceeded: 369559 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 369559 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 369559 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 369559 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 369559 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (369559 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-42168 | 2026-07-22 | 9.1 Critical | ||
| django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. These fields are passed directly to os.system() in pyas2/utils.py without sanitization, allowing an authenticated admin user to execute arbitrary commands on the server when an AS2 message is received or sent. | ||||
| CVE-2026-51833 | 1 Xenforo | 1 Xenforo | 2026-07-22 | 7.5 High |
| Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can enumerate internal services (ports) or expose the original IP address of the server. | ||||
| CVE-2026-52203 | 2026-07-22 | 7.5 High | ||
| An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter. | ||||
| CVE-2026-52348 | 2026-07-22 | 9.8 Critical | ||
| cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java. | ||||
| CVE-2026-51080 | 2026-07-22 | 9.8 Critical | ||
| libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability. | ||||
| CVE-2026-41993 | 2026-07-22 | 4.4 Medium | ||
| Improper Access Control vulnerability in the Removable Media Validation function of TXOne Networks products allows a local attacker with administrator privileges to bypass the file lockdown mechanism, resulting in unauthorized file transfer to the victim device. The attacker needs to deploy unauthorized file on the removable media in advance. This issue affects SafePortAgent: before 3.2.5024; StellarProtect: from 3.2.4011 before 5.0.1083. | ||||
| CVE-2025-50329 | 2026-07-22 | N/A | ||
| An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe. | ||||
| CVE-2025-50327 | 2026-07-22 | N/A | ||
| An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection mechanism | ||||
| CVE-2025-50325 | 2026-07-22 | N/A | ||
| BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of BandiZip | ||||
| CVE-2025-50324 | 2026-07-22 | N/A | ||
| An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component. | ||||
| CVE-2025-44090 | 2026-07-22 | N/A | ||
| An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file. | ||||
| CVE-2025-44089 | 2026-07-22 | N/A | ||
| An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file. | ||||
| CVE-2024-23567 | 2026-07-22 | 4.3 Medium | ||
| HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data passed in this manner can be exposed because it may end up stored in unintended locations, including server logs, local browser history and proxy logs. | ||||
| CVE-2024-23571 | 2026-07-22 | 4.3 Medium | ||
| HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be cached. If sensitive information in application responses is stored in the local cache, then this may be retrieved by other users who have access to the same computer at a future time. | ||||
| CVE-2024-23575 | 2026-07-22 | 5.3 Medium | ||
| HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may use the contents of error messages to help launch another ,more focused attack. | ||||
| CVE-2024-42214 | 2026-07-22 | 5.3 Medium | ||
| HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify their efforts. | ||||
| CVE-2026-61224 | 1 Oracle | 1 Communications Converged Application Server | 2026-07-22 | 8 High |
| Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with network access via TLS to compromise Oracle Communications Converged Application Server. While the vulnerability is in Oracle Communications Converged Application Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H). | ||||
| CVE-2026-16232 | 2026-07-22 | 9.1 Critical | ||
| An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers. | ||||
| CVE-2026-64829 | 2026-07-22 | 7.4 High | ||
| Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot-password reset flow's failure to clear the sessioncode field in qa-include/app/users-edit.php. While the normal password-change flow in qa-include/pages/account.php explicitly clears the sessioncode to invalidate persistent qa_session cookies, the forgot-password handler qa_finish_reset_user() omits this step, allowing any valid persistent cookie issued before the reset to continue authenticating the account after the password reset completes. | ||||
| CVE-2026-62414 | 2026-07-22 | 9.1 Critical | ||
| The Joomla extension Page Builder CK does not properly apply access control to frontend page list views. | ||||