Search
140,640 CVEs · High severity
CVEs (140,640, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 251–275 of 140,640 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9220 | HIGH | 7.5 | 2026-06-26 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initia… | |
| CVE-2026-9213 | HIGH | Patched | 8.1 | 2026-06-09 | A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execut… |
| CVE-2026-9212 | HIGH | Patched | 8.0 | 2026-06-09 | Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confide… |
| CVE-2026-9211 | HIGH | Patched | 8.8 | 2026-06-09 | An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation. |
| CVE-2026-9208 | HIGH | Patched | 8.8 | 2026-05-27 | Tanium addressed an unauthorized code execution vulnerability in Connect. |
| CVE-2026-9207 | HIGH | Patched | 8.8 | 2026-05-27 | Tanium addressed an unauthorized code execution vulnerability in Connect. |
| CVE-2026-9205 | HIGH | Patched | 7.4 | 2026-08-05 | IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function. |
| CVE-2026-9203 | HIGH | Patched | 8.5 | 2026-08-05 | A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protectio… |
| CVE-2026-9201 | HIGH | Patched | 8.8 | 2026-08-05 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mec… |
| CVE-2026-9200 | HIGH | 7.5 | 2026-05-27 | The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2.1 via the shortcode function. This makes it possibl… | |
| CVE-2026-9196 | HIGH | Patched | 8.1 | 2026-08-05 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑g… |
| CVE-2026-9185 | HIGH | 7.5 | 2026-06-09 | The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.22.0 via the `userId` para… | |
| CVE-2026-9179 | HIGH | 7.5 | 2026-06-24 | The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint in versions up to and inc… | |
| CVE-2026-9178 | HIGH | 7.5 | 2026-06-24 | The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the REST route wp/v3/user/… | |
| CVE-2026-9171 | HIGH | 7.5 | 2026-07-17 | IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote att… | |
| CVE-2026-9169 | HIGH | 8.8 | 2026-08-07 | DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by p… | |
| CVE-2026-9165 | HIGH | 7.7 | 2026-07-06 | A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. A… | |
| CVE-2026-9157 | HIGH | Patched | 8.4 | 2026-05-21 | Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remote Code Inclusion. This issue affects Web Fax: from… |
| CVE-2026-9155 | HIGH | 8.8 | 2026-06-25 | OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter… | |
| CVE-2026-9154 | HIGH | 7.1 | 2026-06-25 | Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths … | |
| CVE-2026-9148 | HIGH | 7.2 | 2026-07-03 | The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, 7.6.56 T… | |
| CVE-2026-9147 | HIGH | 7.8 | 2026-07-18 | uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (f… | |
| CVE-2026-9144 | HIGH | 7.6 | 2026-05-20 | Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a stored cross-site scripting vulnerability in the embedded web configuration interface that allows authentica… | |
| CVE-2026-9137 | HIGH | Patched | 7.5 | 2026-05-20 | The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint… |
| CVE-2026-9133 | HIGH | Patched | 7.7 | 2026-05-20 | Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/valida… |