Export limit exceeded: 370925 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 370925 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (370925 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-44089 | 1 Nch Software | 1 Expresszip | 2026-07-27 | 8.8 High |
| An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file. | ||||
| CVE-2025-44090 | 1 Ohsoft | 1 Coffeezip | 2026-07-27 | 8.8 High |
| An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file. | ||||
| CVE-2025-50327 | 1 Fcorbelli | 1 Zpaqfranz | 2026-07-27 | 8.8 High |
| An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection mechanism | ||||
| CVE-2026-16473 | 2 Redhat, Sbc | 2 Enterprise Linux, Sbc | 2026-07-27 | 4.3 Medium |
| A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory. | ||||
| CVE-2026-57599 | 1 Hikvision | 1 Ds-2cd Series | 2026-07-27 | 6.6 Medium |
| There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH. | ||||
| CVE-2026-57600 | 1 Hikvision | 4 Ds-2cd Series, Ds-2de Series, Ds-2dp Series and 1 more | 2026-07-27 | 7.5 High |
| Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data. | ||||
| CVE-2026-61390 | 1 Hikvision | 2 Ds-2cd Series, Ds-2de Series | 2026-07-27 | 7.7 High |
| There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets. | ||||
| CVE-2026-61391 | 1 Hikvision | 2 Ds-2cd Series, Ds-2de Series | 2026-07-27 | 7.2 High |
| There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets. | ||||
| CVE-2026-61392 | 1 Hikvision | 2 Ds-2cd Series, Ds-2de Series | 2026-07-27 | 5.3 Medium |
| There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory. | ||||
| CVE-2026-16551 | 1 Thinkst Applied Research | 1 Opencanary | 2026-07-27 | N/A |
| Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. This issue affects OpenCanary 0.9.8 only. | ||||
| CVE-2026-16552 | 2 Redhat, Systemd | 4 Enterprise Linux, Hardened Images, Openshift Container Platform and 1 more | 2026-07-27 | 6.3 Medium |
| The reported issue is invalid, as it requires root privileges to reproduce, and it is out of scope of the threat model of the affected component. | ||||
| CVE-2026-13069 | 1 Mongodb | 1 Mongodb Server | 2026-07-27 | 6.5 Medium |
| An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unvalidated field used to control an internal computation loop. The resulting resource exhaustion degrades availability for other operations. | ||||
| CVE-2026-13056 | 1 Mongodb | 1 Mongodb Server | 2026-07-27 | 6.5 Medium |
| Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to crash with OOM error. | ||||
| CVE-2026-59531 | 2 Anh Tran, Wordpress | 2 Falcon – Wordpress Optimizations & Tweaks, Wordpress | 2026-07-27 | 7.5 High |
| Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions. | ||||
| CVE-2026-59536 | 2 Cocart Headless, Wordpress | 2 Cocart – Headless Ecommerce, Wordpress | 2026-07-27 | 7.5 High |
| Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions. | ||||
| CVE-2026-59537 | 2 Sender, Wordpress | 2 Sender – Newsletter, Sms And Email Marketing Automation For Woocommerce, Wordpress | 2026-07-27 | 7.6 High |
| Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions. | ||||
| CVE-2026-59548 | 2 Byteflows, Wordpress | 2 Byteflows Travel & Hotel Booking, Wordpress | 2026-07-27 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions. | ||||
| CVE-2026-59552 | 2 Shahadat Hossain, Wordpress | 2 3d Flipbook Pdf Viewer & Embedder, Wordpress | 2026-07-27 | 7.2 High |
| Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. | ||||
| CVE-2026-59557 | 2 Franky, Wordpress | 2 Events Made Easy, Wordpress | 2026-07-27 | 6.5 Medium |
| Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions. | ||||
| CVE-2026-59559 | 2 Themewant, Wordpress | 2 Rt Mega Menu – Mega Menu Builder For Elementor & Gutenberg, Wordpress | 2026-07-27 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. | ||||