Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

140,265 CVEs · High severity

EOL hidden · Show all products

CVEs (140,265, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 251–275 of 140,265 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-85608 HIGH 7.5 2026-09-04 Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthen…
CVE-2026-85607 HIGH 8.8 2026-09-04 Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/r…
CVE-2026-85606 HIGH 7.5 2026-09-04 firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory …
CVE-2026-81832 HIGH 7.7 2026-09-04 IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable t…
CVE-2026-6958 HIGH 7.8 2026-09-04 Acunetix 25.11.251107123 for Windows contains a local privilege escalation vulnerability in the Web Vulnerability Scanning Engine (wvsc.exe) that allows low-privileged loca…
CVE-2026-19205 HIGH Patched 7.5 2026-09-04 Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting. This issue affects GastroMenum Web Panel: before 31.08.2026.
CVE-2026-12483 HIGH 7.5 2026-09-04 The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up to and including 5.1.5. This is due to insufficient input validation in…
CVE-2026-85649 HIGH 7.9 2026-09-04 (Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debi…
CVE-2026-85516 HIGH 7.3 2026-09-04 A vulnerability was detected in code-projects Vehicle Management System 1.0. The affected element is an unknown function of the file /busprofile.php. Performing a manipulat…
CVE-2026-18198 HIGH 8.8 2026-09-04 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN O…
CVE-2026-85617 HIGH Patched 8.8 2026-09-04 snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside thei…
CVE-2026-85616 HIGH Patched 8.5 2026-09-04 Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authentica…
CVE-2026-85614 HIGH Patched 8.6 2026-09-04 OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled …
CVE-2026-85613 HIGH Patched 8.2 2026-09-04 OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute…
CVE-2026-85612 HIGH Patched 7.5 2026-09-04 OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied ur…
CVE-2026-85610 HIGH Patched 8.8 2026-09-04 OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering…
CVE-2026-85609 HIGH Patched 7.5 2026-09-04 Openpanel before 2.3.0 contains an unauthenticated full-read server-side request forgery (SSRF) vulnerability in the GET /tools/site-checker endpoint (apps/api/src/controll…
CVE-2026-85604 HIGH Patched 8.8 2026-09-04 Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes&hellip;
CVE-2026-85599 HIGH Patched 7.2 2026-09-04 Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rende&hellip;
CVE-2026-85585 HIGH 7.5 2026-09-04 SiYuan before v3.8.2 contains an unbounded resource consumption vulnerability in the request-concurrency middleware that retains mutex entries for every unique request path&hellip;
CVE-2026-85584 HIGH 7.5 2026-09-04 SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle that stores failed-attempt state using attacker-controlle&hellip;
CVE-2026-85581 HIGH 7.5 2026-09-04 SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process iden&hellip;
CVE-2026-19080 HIGH Patched 7.5 2026-09-04 Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting. This issue affects Menulux Portal: before 20260903211448.
CVE-2026-19051 HIGH Patched 7.1 2026-09-04 Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data. This issue affects Menulux Portal: before 20&hellip;
CVE-2026-85512 HIGH 7.3 2026-09-04 A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The man&hellip;