Export limit exceeded: 369648 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (369648 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-13462 1 Payrange 1 Payrange 2026-07-23 7.5 High
PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. A remote and unauthenticated attacker can steal information that the user sends.
CVE-2026-43752 1 Claris 1 Filemaker Server 2026-07-23 4.9 Medium
An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.
CVE-2026-13058 1 Mongodb 1 Mongodb Server 2026-07-23 N/A
An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with an incomplete set of required fields. The issue stems from inconsistent validation across related transaction command parameters, resulting in a fatal internal invariant failure and denial of service.
CVE-2026-52686 1 Powerdns 1 Recursor 2026-07-23 3.7 Low
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.
CVE-2026-52688 1 Powerdns 1 Recursor 2026-07-23 7.5 High
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
CVE-2026-16723 1 Alibaba 1 Fastjson 2026-07-23 9 Critical
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
CVE-2026-65713 2026-07-23 N/A
Modals gallery paths could enumerate unintended directories.
CVE-2026-64873 2026-07-23 N/A
Custom query URLs could access internal or reserved network services.
CVE-2026-64871 2026-07-23 N/A
Administrator URL purges did not consistently require a valid token and cache-management permission.
CVE-2026-65757 2026-07-23 N/A
The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens.
CVE-2026-65755 2026-07-23 N/A
Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it should become unavailable.
CVE-2026-65754 2026-07-23 N/A
ReReplacer XML include paths could read files outside the site directory.
CVE-2026-64875 2026-07-23 N/A
GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass.
CVE-2026-64876 2026-07-23 N/A
Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.
CVE-2026-64872 2026-07-23 N/A
Custom purge and log paths could escape the site webroot directory.
CVE-2026-65712 2026-07-23 N/A
CDN versioning could check file paths outside the site directory, exposing local file existence and modification metadata.
CVE-2026-65756 2026-07-23 N/A
Shortcut configuration accepted arbitrary inline JavaScript.
CVE-2026-64874 2026-07-23 N/A
CDN credentials were exposed in administrator request URLs.
CVE-2026-64799 2026-07-23 N/A
Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF, internal-data access or writing attacker-controlled files into a web-accessible folder.
CVE-2026-65430 2026-07-23 N/A
MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.