21745 Total CVEs
12907 AI Analyzed
307 CISA KEV
4769 Critical
All Vendors
Showing 3001-3050 of 21745 CVEs Page 61 of 435
CVE-2026-58426
Analyzed
9.6
Gitea Gitea Open Source Git Server

An HMAC ambiguity in Gitea Actions Artifacts allows cross-repository data reads and cross-task state writes, compromising the integrity and confidenti...

2026-07-04
CVE-2026-58424
Analyzed
8.9
Gitea Gitea Open Source Git Server

Permanent Fork PR Workflow Approval Gate Bypass

2026-07-04
CVE-2026-58423
Analyzed
7.7
Intel Gitea Open Source Git Server

LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

2026-07-04
CVE-2026-58422
Analyzed
9.8
Gitea Open Source Git Server

An improper authorization flaw in the OAuth sign-in callback mechanism allows attackers to silently re-enable previously disabled administrator accoun...

2026-07-07
CVE-2026-58421
Analyzed
7.5
Gitea Open Source Git Server

Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

2026-07-07
CVE-2026-58419
Analyzed
7.5
Intel Gitea Open Source Git Server

Notification API leaks private issue metadata after access revocation

2026-07-07
CVE-2026-58409
Analyzed
9.1
HP CRM

ChurchCRM versions prior to 7.4.0 contain an unrestricted file upload vulnerability that allows an authenticated administrator to achieve remote code...

2026-07-14
CVE-2026-58399
Analyzed
8.7
Antonio Castellon module-auth

@acastellon/auth is an authentication control system for microservices

2026-07-02
CVE-2026-58389
Analyzed
8.7
Apache Apache Thrift

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings

2026-07-28
CVE-2026-58384
Analyzed
7.3
Red Hat GIMP

A flaw was found in GIMP's PSD parser

2026-07-07
CVE-2026-58380
Analyzed
7.3
Red Hat GIMP

A flaw was found in GIMP's PNM file format parser

2026-07-07
CVE-2026-58379
Analyzed
7.3
Red Hat GIMP

A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser

2026-07-05
CVE-2026-58378
Analyzed
8.8
Allwinner H616 TV Box (TV98)

Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production

2026-07-10
CVE-2026-58377
Analyzed
8.1
JeecgBoot JeecgBoot

JeecgBoot through 3

2026-07-01
CVE-2026-58376
Analyzed
7.6
Dolibarr Dolibarr ERP/CRM

Dolibarr through 23

2026-07-01
CVE-2026-58372
Analyzed
8.1
SeaweedFS SeaweedFS

SeaweedFS before 4

2026-07-01
CVE-2026-58370
Analyzed
8.1
Woodpecker Woodpecker CI

Woodpecker before 3

2026-07-01
CVE-2026-58302
Analyzed
8.4
Linux LinuxCNC

rtapi_app in linuxcnc-uspace in LinuxCNC before 2

2026-06-30
CVE-2026-5830
8.8
Tenda AC15

A vulnerability was identified in Tenda AC15 15

2026-04-09
CVE-2026-58299
Analyzed
7.5
Google Edge (Chromium-based)

Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network

2026-07-05
CVE-2026-58298
Analyzed
7.2
Microsoft Edge (Chromium-based)

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacke...

2026-07-05
CVE-2026-58297
Analyzed
7.1
Google Edge (Chromium-based)

Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose informatio...

2026-07-05
CVE-2026-58296
Analyzed
7.1
Google Edge (Chromium-based)

Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose informatio...

2026-07-05
CVE-2026-58295
Analyzed
8.3
Microsoft Edge (Chromium-based)

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security...

2026-07-04
CVE-2026-58294
Analyzed
7.5
Microsoft Edge (Chromium-based)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network

2026-07-05
CVE-2026-58293
Analyzed
8.1
Microsoft Edge (Chromium-based)

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network

2026-07-04
CVE-2026-58292
Analyzed
7.5
Microsoft Edge (Chromium-based)

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network

2026-07-05
CVE-2026-58290
Analyzed
7.5
Microsoft Edge (Chromium-based)

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over...

2026-07-05
CVE-2026-58289
Analyzed
9
Microsoft Edge (Chromium-based)

A type confusion vulnerability in Microsoft Edge (Chromium-based) allows an unauthorized remote attacker to execute arbitrary code.

2026-07-04
CVE-2026-58288
Analyzed
8.3
Microsoft Edge (Chromium-based)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network

2026-07-04
CVE-2026-58287
Analyzed
8.3
Microsoft Edge (Chromium-based)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network

2026-07-04
CVE-2026-58286
Analyzed
8.1
Microsoft Edge (Chromium-based)

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network

2026-07-04
CVE-2026-58285
Analyzed
8.3
Microsoft Edge

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over...

2026-07-04
CVE-2026-58284
Analyzed
8.3
Microsoft Edge

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network

2026-07-04
CVE-2026-58283
Analyzed
8.1
Microsoft Edge (Chromium-based)

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing o...

2026-07-04
CVE-2026-58282
Analyzed
8.1
Microsoft Edge (Chromium-based)

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network

2026-07-04
CVE-2026-58281
Analyzed
8.3
Microsoft Microsoft Edge (Chromium-based)

Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network

2026-07-12
CVE-2026-58277
Analyzed
8.8
Microsoft SharePoint Enterprise Server

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network

2026-07-15
CVE-2026-58276
Analyzed
7.5
Microsoft Edge (Chromium-based)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network

2026-07-05
CVE-2026-58275
Analyzed
10
Microsoft Azure DNS

A missing authorization vulnerability in Microsoft Azure DNS allows unauthenticated, remote attackers to escalate privileges over a network.

2026-07-25
CVE-2026-58262
Analyzed
7.1
Unknown klever-go

Klever-Go is the Go implementation of the Klever blockchain protocol

2026-08-09
CVE-2026-58253
Analyzed
8.8
NATS.io nats-server

NATS Server is a high-performance server for NATS

2026-07-09
CVE-2026-58243
Analyzed
8.8
SAP SAP ABAP Developer Tools

SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to exec...

2026-08-11
CVE-2026-58233
Analyzed
7.6
SAP SAP Change and Transport System Attach Tool (ctsattach)

SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when proces...

2026-07-14
CVE-2026-58231
Analyzed
10
SAP SAP Commerce Cloud (Data Hub Adapter)

SAP Commerce Cloud (Data Hub Adapter) is vulnerable to code injection, allowing unauthenticated attackers to execute arbitrary code by sending crafted...

2026-08-12
CVE-2026-58227
Analyzed
8.7
Erlang OTP

The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS or DTLS handshake

2026-07-28
CVE-2026-58226
Analyzed
8.7
HP HPAX

Inefficient Algorithmic Complexity vulnerability in elixir-mint hpax allows unauthenticated denial-of-service via unbounded HPACK integer decoding

2026-07-07
CVE-2026-58222
Analyzed
8.8
Red Hat Red Hat Enterprise Linux

A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC)

2026-07-31
CVE-2026-5821
Analyzed
8.1
WordPress Image Optimizer – Optimize Images and Convert to WebP or AVIF

The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1

2026-07-03
CVE-2026-58195
Analyzed
8.8
Unknown agentic-flow

Agentic-Flow is an AI agent orchestration platform

2026-07-18