Export limit exceeded: 18671 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (18671 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16560 | 1 Redhat | 2 Directory Server, Enterprise Linux | 2026-07-22 | 5.3 Medium |
| A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the same memory pointer causing a denial of service or an arbitrary memory write operation. | ||||
| CVE-2026-16544 | 1 Redhat | 1 Ansible Automation Platform | 2026-07-22 | 6.5 Medium |
| A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workflow_events, ad_hoc_command_events). Three event groups - inventory_update_events, project_update_events, and system_job_events — are not mapped, causing the authorization check to be skipped. Any authenticated user can subscribe to these unmapped websocket event groups for any object ID and receive real-time stdout output from jobs belonging to organizations they have no access to. This is an incomplete remediation of CVE-2020-10698. | ||||
| CVE-2026-60080 | 1 Apache | 1 Fory | 2026-07-22 | 7.3 High |
| Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure. Users are recommended to upgrade to version 1.4.0, which fixes the issue. | ||||
| CVE-2026-44187 | 1 Redhat | 1 Ansible Automation Platform | 2026-07-22 | 3.3 Low |
| A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. The extension insecurely stores the API key in plain text within the user's configuration file and writes it to output log files. This information disclosure can lead to the attacker obtaining the API credential and potentially consuming the user's API quota. | ||||
| CVE-2026-65603 | 1 Getgrav | 1 Grav | 2026-07-22 | 8.8 High |
| The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile self-update handler (processUserProfile(), the update_user task). Unlike the registration handler, this handler does not strip privilege fields ('groups','access') from user-submitted form data before persisting them. When an administrator has added 'groups' and/or 'access' to plugins.login.user_registration.fields and the default 'regular'/DataUser account backend is in use, a low-privilege authenticated user can POST crafted profile form data (e.g. access[admin][super]=true) to escalate to super-admin, enabling admin panel access, scheduler abuse (RCE), and Twig evaluation. Fixed in 3.8.12. | ||||
| CVE-2026-65597 | 1 N8n | 1 N8n | 2026-07-22 | N/A |
| n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML preview, which renders execution output into an iframe srcdoc without the sandbox attribute. A sanitizer bypass allows injected script to execute same-origin as the editor. When a victim opens the preview, the script can call authenticated APIs using the victim's session. An account with global:member privileges can exploit the issue. | ||||
| CVE-2026-65591 | 1 N8n | 1 N8n | 2026-07-22 | N/A |
| n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions can craft a malicious expression to bypass the sanitizer and achieve host-level code execution as the n8n process. The legacy expression engine is the default in affected versions. Fixed in n8n 1.123.64, 2.29.8, and 2.30.1. | ||||
| CVE-2026-16082 | 1 Sipeed | 1 Picoclaw | 2026-07-22 | 5.3 Medium |
| A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun of the file pkg/agent/pipeline_execute.go. The manipulation of the argument cwe leads to time-of-check time-of-use. The attack must be carried out locally. The exploit is publicly available and might be used. The reported GitHub issue was closed automatically with the label "not planned" by a bot. | ||||
| CVE-2026-16129 | 1 Princezuda | 1 Safestclaw | 2026-07-22 | 5.3 Medium |
| A vulnerability has been found in princezuda SafestClaw up to 4.2.4. This vulnerability affects the function ShellAction._validate_command of the file src/safestclaw/actions/shell.py of the component Built-in Web Interface. Such manipulation leads to incomplete blacklist. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The presence of this vulnerability remains uncertain at this time. The project maintainer explains: "On paper you're correct, this is a vulnerability. In practice, nothing your AI generated shows how it makes users vulnerable. It's open source. Someone can mod the shell allow list or remove that system. Present an actual poc that shows a threat to users." | ||||
| CVE-2026-50304 | 1 Microsoft | 10 .net, .net Framework, Windows 10 1607 and 7 more | 2026-07-22 | 7.5 High |
| Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-50649 | 2 Microsoft, Redhat | 4 .net, .net Framework, Visual Studio 2026 and 1 more | 2026-07-22 | 7.8 High |
| Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-50647 | 1 Microsoft | 15 .net, .net Framework, Windows 10 1607 and 12 more | 2026-07-22 | 7.5 High |
| Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-50525 | 2 Microsoft, Redhat | 5 .net, .net Framework, Visual Studio 2022 and 2 more | 2026-07-22 | 7.5 High |
| Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-50411 | 1 Microsoft | 15 .net, .net Framework, Windows 10 1607 and 12 more | 2026-07-22 | 7.5 High |
| Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-50355 | 1 Microsoft | 10 .net, .net Framework, Windows 10 1607 and 7 more | 2026-07-22 | 7.5 High |
| Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-50324 | 1 Microsoft | 9 .net, .net Framework, Windows 10 1607 and 6 more | 2026-07-22 | 5.9 Medium |
| Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-50368 | 1 Microsoft | 10 .net, .net Framework, Windows 10 1607 and 7 more | 2026-07-22 | 7.5 High |
| Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-47304 | 1 Microsoft | 6 .net, .net Framework, Visual Studio 2017 and 3 more | 2026-07-22 | 8.1 High |
| Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. | ||||
| CVE-2026-50653 | 1 Microsoft | 3 .net, .net Framework, Azure Active Directory | 2026-07-22 | 7.5 High |
| Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-50652 | 1 Microsoft | 3 .net, .net Framework, Azure Active Directory | 2026-07-22 | 7.5 High |
| Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. | ||||