Filter and search through 392,438 vulnerabilities
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-22609 | #Fickling's assessment `ctypes`, `importlib`, `runpy`, `code` and `multiprocessing` were added the list of unsafe imports (https://github.com/trailof... | 7.8 | 560 | Neutral | No |
| Yes |
| CVE-2026-22608 | # Fickling's assessment `pydoc` and `ctypes` were added to the list of unsafe imports (https://github.com/trailofbits/fickling/commit/b793563e60a5e03... | 7.8 | 560 | Neutral | No | Yes |
| CVE-2026-22607 | # Fickling's assessment `cProfile` was added to the list of unsafe imports (https://github.com/trailofbits/fickling/commit/dc8ae12966edee27a78fe05c57... | 7.8 | 560 | Neutral | No | Yes |
| CVE-2026-22606 | # Fickling's assessment `runpy` was added to the list of unsafe imports (https://github.com/trailofbits/fickling/commit/9a2b3f89bd0598b528d62c10a64c... | 7.8 | 560 | Neutral | No | Yes |
| CVE-2026-22605 | OpenProject is an open-source, web-based project management software. OpenProject versions prior to version 16.6.3, allowed users with the View Meetin... | 4.3 | 99 | Neutral | No | Yes |
| CVE-2026-22604 | OpenProject is an open-source, web-based project management software. For OpenProject versions from 11.2.1 to before 16.6.2, when sending a POST reque... | 5.3 | 124 | Neutral | No | Yes |
| CVE-2026-22603 | OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, OpenProject’s unauthenticated password-change endpoint ... | 6.5 | 216 | Neutral | No | Yes |
| CVE-2026-22602 | OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, a low‑privileged logged-in user can view the full names... | 3.5 | 88 | Neutral | No | Yes |
| CVE-2026-22601 | OpenProject is an open-source, web-based project management software. For OpenProject version 16.6.1 and below, a registered administrator can execute... | 7.2 | 313 | Neutral | No | Yes |
| CVE-2026-22600 | OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export func... | 9.1 | 563 | Neutral | No | Yes |
| CVE-2026-22598 | ManageIQ is an open-source management platform. A flaw was found in the ManageIQ API prior to version radjabov-2 where a malformed TimeProfile could b... | 0.0 | 0 | Neutral | No | No |
| CVE-2026-22597 | ### Impact A vulnerability in Ghost’s media inliner mechanism allows staff users in possession of a valid authentication token for the Ghost Admin API... | 2.7 | 212 | Neutral | No | Yes |
| CVE-2026-22596 | ### Impact A vulnerability in Ghost's `/ghost/api/admin/members/events` endpoint allows users with authentication credentials for the Admin API to exe... | 7.2 | 442 | Neutral | No | Yes |
| CVE-2026-22595 | ### Impact A vulnerability in Ghost's handling of Staff Token authentication allowed certain endpoints to be accessed that were only intended to be ac... | 8.1 | 540 | Neutral | No | Yes |
| CVE-2026-22594 | ### Impact A vulnerability in Ghost's 2FA mechanism allows staff users to skip email 2FA. ### Vulnerable versions This vulnerability is present in Gh... | 8.1 | 476 | Neutral | No | Yes |
| CVE-2026-22589 | ### Summary An Unauthenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that allows an unauthenticated attacker to access ... | 7.5 | 407 | Neutral | No | Yes |
| CVE-2026-22588 | ### Summary An Authenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that allows an authenticated user to retrieve other ... | 6.5 | 231 | Neutral | No | Yes |
| CVE-2026-22587 | Ideagen DevonWay contains a stored cross site scripting vulnerability. A remote, authenticated attacker could craft a payload in the 'Reports' page th... | 5.5 | 234 | Neutral | No | No |
| CVE-2026-22586 | Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Cen... | 9.8 | 596 | Neutral | No | No |
| CVE-2026-22585 | Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Cent... | 9.8 | 596 | Neutral | No | No |