Search
140,640 CVEs · High severity
CVEs (140,640, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 276–300 of 140,640 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9130 | HIGH | Patched | 7.1 | 2026-08-05 | IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other u… |
| CVE-2026-9128 | HIGH | Patched | 7.5 | 2026-07-14 | A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified… |
| CVE-2026-9127 | HIGH | Patched | 7.5 | 2026-07-14 | A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated us… |
| CVE-2026-9126 | HIGH | Patched | 8.8 | 2026-05-20 | Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium se… |
| CVE-2026-9123 | HIGH | Patched | 7.5 | 2026-05-20 | Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a sandbox … |
| CVE-2026-9121 | HIGH | Patched | 8.8 | 2026-05-20 | Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium se… |
| CVE-2026-9120 | HIGH | Patched | 8.8 | 2026-05-20 | Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-9119 | HIGH | Patched | 8.8 | 2026-05-20 | Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch… |
| CVE-2026-9118 | HIGH | Patched | 8.8 | 2026-05-20 | Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security sev… |
| CVE-2026-9117 | HIGH | Patched | 7.5 | 2026-05-20 | Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to potentially perform … |
| CVE-2026-9114 | HIGH | Patched | 8.8 | 2026-05-20 | Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chro… |
| CVE-2026-9112 | HIGH | Patched | 8.8 | 2026-05-20 | Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chr… |
| CVE-2026-9111 | HIGH | Patched | 8.8 | 2026-05-20 | Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security s… |
| CVE-2026-9109 | HIGH | 7.2 | 2026-06-13 | The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API… | |
| CVE-2026-9108 | HIGH | Patched | 7.5 | 2026-07-14 | A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize … |
| CVE-2026-9099 | HIGH | Patched | 7.7 | 2026-06-25 | A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited adm… |
| CVE-2026-9096 | HIGH | 7.5 | 2026-05-28 | Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefor… | |
| CVE-2026-9095 | HIGH | 8.1 | 2026-05-28 | Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.Retrieve… | |
| CVE-2026-9089 | HIGH | Patched | 8.8 | 2026-05-21 | The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in A… |
| CVE-2026-9086 | HIGH | Patched | 7.3 | 2026-06-25 | A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to client registration endpoint… |
| CVE-2026-9085 | HIGH | Patched | 8.8 | 2026-07-05 | Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-Parental-Cont… |
| CVE-2026-9081 | HIGH | Patched | 7.1 | 2026-08-05 | IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function fo… |
| CVE-2026-9080 | HIGH | Patched | 7.3 | 2026-07-03 | Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using … |
| CVE-2026-9077 | HIGH | Patched | 8.5 | 2026-08-05 | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to … |
| CVE-2026-9076 | HIGH | Patched | 7.5 | 2026-06-09 | Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a… |