Export limit exceeded: 369648 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (369648 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-13462 | 1 Payrange | 1 Payrange | 2026-07-23 | 7.5 High |
| PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. A remote and unauthenticated attacker can steal information that the user sends. | ||||
| CVE-2026-43752 | 1 Claris | 1 Filemaker Server | 2026-07-23 | 4.9 Medium |
| An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1. | ||||
| CVE-2026-13058 | 1 Mongodb | 1 Mongodb Server | 2026-07-23 | N/A |
| An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with an incomplete set of required fields. The issue stems from inconsistent validation across related transaction command parameters, resulting in a fatal internal invariant failure and denial of service. | ||||
| CVE-2026-52686 | 1 Powerdns | 1 Recursor | 2026-07-23 | 3.7 Low |
| The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record. | ||||
| CVE-2026-52688 | 1 Powerdns | 1 Recursor | 2026-07-23 | 7.5 High |
| RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation | ||||
| CVE-2026-16723 | 1 Alibaba | 1 Fastjson | 2026-07-23 | 9 Critical |
| A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required. | ||||
| CVE-2026-65713 | 2026-07-23 | N/A | ||
| Modals gallery paths could enumerate unintended directories. | ||||
| CVE-2026-64873 | 2026-07-23 | N/A | ||
| Custom query URLs could access internal or reserved network services. | ||||
| CVE-2026-64871 | 2026-07-23 | N/A | ||
| Administrator URL purges did not consistently require a valid token and cache-management permission. | ||||
| CVE-2026-65757 | 2026-07-23 | N/A | ||
| The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens. | ||||
| CVE-2026-65755 | 2026-07-23 | N/A | ||
| Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it should become unavailable. | ||||
| CVE-2026-65754 | 2026-07-23 | N/A | ||
| ReReplacer XML include paths could read files outside the site directory. | ||||
| CVE-2026-64875 | 2026-07-23 | N/A | ||
| GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass. | ||||
| CVE-2026-64876 | 2026-07-23 | N/A | ||
| Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates. | ||||
| CVE-2026-64872 | 2026-07-23 | N/A | ||
| Custom purge and log paths could escape the site webroot directory. | ||||
| CVE-2026-65712 | 2026-07-23 | N/A | ||
| CDN versioning could check file paths outside the site directory, exposing local file existence and modification metadata. | ||||
| CVE-2026-65756 | 2026-07-23 | N/A | ||
| Shortcut configuration accepted arbitrary inline JavaScript. | ||||
| CVE-2026-64874 | 2026-07-23 | N/A | ||
| CDN credentials were exposed in administrator request URLs. | ||||
| CVE-2026-64799 | 2026-07-23 | N/A | ||
| Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF, internal-data access or writing attacker-controlled files into a web-accessible folder. | ||||
| CVE-2026-65430 | 2026-07-23 | N/A | ||
| MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability. | ||||