Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

140,640 CVEs · High severity

CVEs (140,640, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 251–275 of 140,640 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9220 HIGH 7.5 2026-06-26 Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initia…
CVE-2026-9213 HIGH Patched 8.1 2026-06-09 A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execut…
CVE-2026-9212 HIGH Patched 8.0 2026-06-09 Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confide…
CVE-2026-9211 HIGH Patched 8.8 2026-06-09 An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.
CVE-2026-9208 HIGH Patched 8.8 2026-05-27 Tanium addressed an unauthorized code execution vulnerability in Connect.
CVE-2026-9207 HIGH Patched 8.8 2026-05-27 Tanium addressed an unauthorized code execution vulnerability in Connect.
CVE-2026-9205 HIGH Patched 7.4 2026-08-05 IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
CVE-2026-9203 HIGH Patched 8.5 2026-08-05 A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protectio…
CVE-2026-9201 HIGH Patched 8.8 2026-08-05 IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mec…
CVE-2026-9200 HIGH 7.5 2026-05-27 The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2.1 via the shortcode function. This makes it possibl…
CVE-2026-9196 HIGH Patched 8.1 2026-08-05 IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑g…
CVE-2026-9185 HIGH 7.5 2026-06-09 The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.22.0 via the `userId` para…
CVE-2026-9179 HIGH 7.5 2026-06-24 The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint in versions up to and inc…
CVE-2026-9178 HIGH 7.5 2026-06-24 The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the REST route wp/v3/user/…
CVE-2026-9171 HIGH 7.5 2026-07-17 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote att…
CVE-2026-9169 HIGH 8.8 2026-08-07 DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by p…
CVE-2026-9165 HIGH 7.7 2026-07-06 A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. A…
CVE-2026-9157 HIGH Patched 8.4 2026-05-21 Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remote Code Inclusion. This issue affects Web Fax: from…
CVE-2026-9155 HIGH 8.8 2026-06-25 OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter…
CVE-2026-9154 HIGH 7.1 2026-06-25 Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths …
CVE-2026-9148 HIGH 7.2 2026-07-03 The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, 7.6.56 T…
CVE-2026-9147 HIGH 7.8 2026-07-18 uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (f…
CVE-2026-9144 HIGH 7.6 2026-05-20 Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a stored cross-site scripting vulnerability in the embedded web configuration interface that allows authentica…
CVE-2026-9137 HIGH Patched 7.5 2026-05-20 The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint…
CVE-2026-9133 HIGH Patched 7.7 2026-05-20 Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/valida…