Search
140,640 CVEs · High severity
CVEs (140,640, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 226–250 of 140,640 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9348 | HIGH | 8.8 | 2026-05-24 | A vulnerability was found in Edimax EW-7438RPn up to 1.31. Affected by this vulnerability is an unknown functionality of the file /goform/mp of the component webs. The mani… | |
| CVE-2026-9346 | HIGH | 8.8 | 2026-05-24 | A flaw has been found in Edimax EW-7438RPn up to 1.31. This impacts the function formWirelessTbl of the file /goform/formWirelessTbl of the component webs. Executing a mani… | |
| CVE-2026-9345 | HIGH | 8.8 | 2026-05-24 | A vulnerability was detected in Edimax EW-7438RPn up to 1.31. This affects the function formWizSurvey of the file /goform/formWizSurvey of the component webs. Performing a … | |
| CVE-2026-9344 | HIGH | 8.8 | 2026-05-24 | A security vulnerability has been detected in Edimax EW-7438RPn up to 1.31. The impacted element is an unknown function of the file /goform/formWpsStart of the component we… | |
| CVE-2026-9334 | HIGH | Patched | 7.3 | 2026-06-03 | Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses duplicate object k… |
| CVE-2026-9331 | HIGH | 7.1 | 2026-09-08 | The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing … | |
| CVE-2026-9330 | HIGH | Patched | 8.5 | 2026-06-01 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component… |
| CVE-2026-9323 | HIGH | 8.1 | 2026-07-18 | The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that … | |
| CVE-2026-9322 | HIGH | Patched | 7.5 | 2026-07-30 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted H… |
| CVE-2026-9317 | HIGH | Patched | 8.1 | 2026-09-04 | Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by … |
| CVE-2026-9312 | HIGH | Patched | 8.2 | 2026-05-27 | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal … |
| CVE-2026-9295 | HIGH | 8.8 | 2026-05-23 | A security flaw has been discovered in Edimax BR-6428NS 1.10. This affects the function formWirelessTbl of the file /goform/formWirelessTbl of the component POST Request Ha… | |
| CVE-2026-9294 | HIGH | 8.8 | 2026-05-23 | A vulnerability was identified in Edimax BR-6428NS 1.10. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST … | |
| CVE-2026-9291 | HIGH | Patched | 7.1 | 2026-05-22 | Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write access to the job… |
| CVE-2026-9290 | HIGH | 7.5 | 2026-06-06 | The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (pro… | |
| CVE-2026-9284 | HIGH | 8.2 | 2026-05-23 | The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the … | |
| CVE-2026-9282 | HIGH | 7.5 | 2026-07-11 | The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possib… | |
| CVE-2026-9277 | HIGH | 8.1 | 2026-05-22 | shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by chara… | |
| CVE-2026-9272 | HIGH | Patched | 8.1 | 2026-07-02 | In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detect… |
| CVE-2026-9256 | HIGH | Patched | 8.1 | 2026-05-22 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with di… |
| CVE-2026-9255 | HIGH | Patched | 7.8 | 2026-05-22 | Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, wit… |
| CVE-2026-9253 | HIGH | 7.2 | 2026-07-09 | The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' parameter in all versio… | |
| CVE-2026-9227 | HIGH | 8.8 | 2026-05-28 | The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.20.1 via the gutenbee_file_and_ext_json … | |
| CVE-2026-9222 | HIGH | 8.1 | 2026-06-26 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. Thi… | |
| CVE-2026-9221 | HIGH | 7.5 | 2026-06-26 | The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating communications between th… |