Vulnerabilities (CVE)

Total 404131 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-29174 1 Craftcms 1 Craft Commerce 2026-06-17 N/A 8.8 HIGH
Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Craft Commerce is vulnerable to SQL Injection in the inventory levels table data endpoint. The sort[0][direction] and sort[0][sortField] parameters are concatenated directly into an addOrderBy() clause without any validation or sanitization. An authenticated attacker with access to the Commerce Inventory section can inject arbitrary SQL queries, potentially leading to a full database compromise. This vulnerability is fixed in 5.5.3.
CVE-2026-29173 1 Craftcms 1 Craft Commerce 2026-06-17 N/A 4.8 MEDIUM
Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a stored XSS vulnerability exists when a user tries to update the Order Status from the Commerce Orders Table. The Order Status Name is rendered without proper escaping, allowing script execution to occur. This vulnerability is fixed in 4.10.2 and 5.5.3.
CVE-2026-29172 1 Craftcms 1 Craft Commerce 2026-06-17 N/A 8.8 HIGH
Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, Craft Commerce is vulnerable to SQL Injection in the purchasables table endpoint. The sort parameter is split by | and the first part (column name) is passed directly as an array key to orderBy() without whitelist validation. Yii2's query builder does NOT escape array keys, allowing an authenticated attacker to inject arbitrary SQL into the ORDER BY clause. This vulnerability is fixed in 4.10.2 and 5.5.3.
CVE-2026-29169 1 Apache 1 Http Server 2026-06-17 N/A 7.5 HIGH
A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.
CVE-2026-29168 1 Apache 1 Http Server 2026-06-17 N/A 7.3 HIGH
Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
CVE-2026-29145 1 Apache 2 Tomcat, Tomcat Native 2026-06-17 N/A 9.1 CRITICAL
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.
CVE-2026-29144 1 Seppmail 1 Secure Email Gateway 2026-06-17 N/A 5.3 MEDIUM
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge security tags using Unicode lookalike characters.
CVE-2026-29143 1 Seppmail 1 Secure Email Gateway 2026-06-17 N/A 9.1 CRITICAL
SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an attacker to control trusted headers.
CVE-2026-29142 1 Seppmail 1 Secure Email Gateway 2026-06-17 N/A 5.3 MEDIUM
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email.
CVE-2026-29141 1 Seppmail 1 Secure Email Gateway 2026-06-17 N/A 5.3 MEDIUM
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK].
CVE-2026-29140 1 Seppmail 1 Secure Email Gateway 2026-06-17 N/A 5.3 MEDIUM
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be used for future encryption to a victim by adding the certificates to S/MIME signatures.
CVE-2026-29139 1 Seppmail 1 Secure Email Gateway 2026-06-17 N/A 9.8 CRITICAL
SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password.
CVE-2026-29138 1 Seppmail 1 Secure Email Gateway 2026-06-17 N/A 7.5 HIGH
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim another user's PGP signature as their own.
CVE-2026-29137 1 Seppmail 1 Secure Email Gateway 2026-06-17 N/A 5.3 MEDIUM
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from users by crafting a long subject.
CVE-2026-29136 1 Seppmail 1 Secure Email Gateway 2026-06-17 N/A 6.1 MEDIUM
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to inject HTML into notification emails about new CA certificates.
CVE-2026-29135 1 Seppmail 1 Secure Email Gateway 2026-06-17 N/A 7.5 HIGH
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag that bypasses subject sanitization.
CVE-2026-29134 1 Seppmail 1 Secure Email Gateway 2026-06-17 N/A 7.5 HIGH
SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass per-domain restrictions.
CVE-2026-29133 1 Seppmail 1 Secure Email Gateway 2026-06-17 N/A 9.1 CRITICAL
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address.
CVE-2026-29132 1 Seppmail 1 Secure Email Gateway 2026-06-17 N/A 7.5 HIGH
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker with access to a victim's GINA account to bypass a second-password check and read protected emails.
CVE-2026-29131 1 Seppmail 1 Secure Email Gateway 2026-06-17 N/A 7.5 HIGH
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to read the contents of emails encrypted for other users.