Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,217 CVEs

CVEs (30,217, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 251–275 of 30,217 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9077 HIGH Patched 8.5 2026-08-05 IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to …
CVE-2026-9074 CRITICAL Patched 9.1 2026-07-08 IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
CVE-2026-9073 MEDIUM 6.2 2026-06-23 A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism log…
CVE-2026-9072 HIGH Patched 8.1 2026-06-22 IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulne…
CVE-2026-9071 HIGH Patched 7.5 2026-06-22 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by send…
CVE-2026-9067 CRITICAL Patched 9.1 2026-06-10 The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the …
CVE-2026-9066 MEDIUM Patched 6.1 2026-07-23 The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of Java…
CVE-2026-9062 LOW Patched 3.4 2026-06-13 The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read …
CVE-2026-9061 LOW Patched 3.5 2026-06-13 The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and outputting it on the Store Locator WordPress plugin b…
CVE-2026-9060 LOW Patched 3.5 2026-06-10 The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store Locator WordPress plugin b…
CVE-2026-9055 CRITICAL 9.8 2026-09-02 The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insuf…
CVE-2026-9052 NONE — 2026-08-21 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-9046 HIGH 7.0 2026-07-16 A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, tha…
CVE-2026-9045 HIGH 7.8 2026-06-10 During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a loc…
CVE-2026-9044 HIGH Patched 8.0 2026-07-31 An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitra…
CVE-2026-9040 NONE — 2026-09-08 A race condition vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local no…
CVE-2026-9036 MEDIUM 5.9 2026-09-03 IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitiv…
CVE-2026-9034 NONE — 2026-09-08 Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a n…
CVE-2026-9033 NONE — 2026-08-20 An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout o…
CVE-2026-9031 NONE — 2026-08-07 An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by internal flash-write ha…
CVE-2026-9030 NONE — 2026-08-07 A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction handlng path in httpd does not properly synchronize or …
CVE-2026-9029 HIGH 7.3 2026-06-22 A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in…
CVE-2026-9028 MEDIUM 5.3 2026-07-09 The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.7.4. This is due to the plugin …
CVE-2026-9027 MEDIUM 5.3 2026-07-09 The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification of Cryptographic Signature in all versions up to, a…
CVE-2026-9021 MEDIUM 5.3 2026-07-09 The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. This is due to the plugin registering the easy_invoic…