Search
11,582 CVEs · High severity
CVEs (11,582, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 251–275 of 11,582 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-85608 | HIGH | 7.5 | 2026-09-04 | Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthen… | |
| CVE-2026-85607 | HIGH | 8.8 | 2026-09-04 | Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/r… | |
| CVE-2026-85606 | HIGH | 7.5 | 2026-09-04 | firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory … | |
| CVE-2026-81832 | HIGH | 7.7 | 2026-09-04 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable t… | |
| CVE-2026-6958 | HIGH | 7.8 | 2026-09-04 | Acunetix 25.11.251107123 for Windows contains a local privilege escalation vulnerability in the Web Vulnerability Scanning Engine (wvsc.exe) that allows low-privileged loca… | |
| CVE-2026-19205 | HIGH | Patched | 7.5 | 2026-09-04 | Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting. This issue affects GastroMenum Web Panel: before 31.08.2026. |
| CVE-2026-12483 | HIGH | 7.5 | 2026-09-04 | The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up to and including 5.1.5. This is due to insufficient input validation in… | |
| CVE-2026-85649 | HIGH | 7.9 | 2026-09-04 | (Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debi… | |
| CVE-2026-85516 | HIGH | 7.3 | 2026-09-04 | A vulnerability was detected in code-projects Vehicle Management System 1.0. The affected element is an unknown function of the file /busprofile.php. Performing a manipulat… | |
| CVE-2026-18198 | HIGH | 8.8 | 2026-09-04 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN O… | |
| CVE-2026-85617 | HIGH | Patched | 8.8 | 2026-09-04 | snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside thei… |
| CVE-2026-85616 | HIGH | Patched | 8.5 | 2026-09-04 | Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authentica… |
| CVE-2026-85614 | HIGH | Patched | 8.6 | 2026-09-04 | OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled … |
| CVE-2026-85613 | HIGH | Patched | 8.2 | 2026-09-04 | OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute… |
| CVE-2026-85612 | HIGH | Patched | 7.5 | 2026-09-04 | OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied ur… |
| CVE-2026-85610 | HIGH | Patched | 8.8 | 2026-09-04 | OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering… |
| CVE-2026-85609 | HIGH | Patched | 7.5 | 2026-09-04 | Openpanel before 2.3.0 contains an unauthenticated full-read server-side request forgery (SSRF) vulnerability in the GET /tools/site-checker endpoint (apps/api/src/controll… |
| CVE-2026-85604 | HIGH | Patched | 8.8 | 2026-09-04 | Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes… |
| CVE-2026-85599 | HIGH | Patched | 7.2 | 2026-09-04 | Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rende… |
| CVE-2026-85585 | HIGH | 7.5 | 2026-09-04 | SiYuan before v3.8.2 contains an unbounded resource consumption vulnerability in the request-concurrency middleware that retains mutex entries for every unique request path… | |
| CVE-2026-85584 | HIGH | 7.5 | 2026-09-04 | SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle that stores failed-attempt state using attacker-controlle… | |
| CVE-2026-85581 | HIGH | 7.5 | 2026-09-04 | SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process iden… | |
| CVE-2026-19080 | HIGH | Patched | 7.5 | 2026-09-04 | Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting. This issue affects Menulux Portal: before 20260903211448. |
| CVE-2026-19051 | HIGH | Patched | 7.1 | 2026-09-04 | Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data. This issue affects Menulux Portal: before 20… |
| CVE-2026-85512 | HIGH | 7.3 | 2026-09-04 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The man… |