Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

140,640 CVEs · High severity

CVEs (140,640, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 276–300 of 140,640 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9130 HIGH Patched 7.1 2026-08-05 IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other u…
CVE-2026-9128 HIGH Patched 7.5 2026-07-14 A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified…
CVE-2026-9127 HIGH Patched 7.5 2026-07-14 A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated us…
CVE-2026-9126 HIGH Patched 8.8 2026-05-20 Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium se…
CVE-2026-9123 HIGH Patched 7.5 2026-05-20 Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a sandbox …
CVE-2026-9121 HIGH Patched 8.8 2026-05-20 Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium se…
CVE-2026-9120 HIGH Patched 8.8 2026-05-20 Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVE-2026-9119 HIGH Patched 8.8 2026-05-20 Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch…
CVE-2026-9118 HIGH Patched 8.8 2026-05-20 Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security sev…
CVE-2026-9117 HIGH Patched 7.5 2026-05-20 Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to potentially perform …
CVE-2026-9114 HIGH Patched 8.8 2026-05-20 Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chro…
CVE-2026-9112 HIGH Patched 8.8 2026-05-20 Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chr…
CVE-2026-9111 HIGH Patched 8.8 2026-05-20 Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security s…
CVE-2026-9109 HIGH 7.2 2026-06-13 The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API…
CVE-2026-9108 HIGH Patched 7.5 2026-07-14 A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize …
CVE-2026-9099 HIGH Patched 7.7 2026-06-25 A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited adm…
CVE-2026-9096 HIGH 7.5 2026-05-28 Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefor…
CVE-2026-9095 HIGH 8.1 2026-05-28 Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.Retrieve…
CVE-2026-9089 HIGH Patched 8.8 2026-05-21 The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in A…
CVE-2026-9086 HIGH Patched 7.3 2026-06-25 A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to client registration endpoint…
CVE-2026-9085 HIGH Patched 8.8 2026-07-05 Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-Parental-Cont…
CVE-2026-9081 HIGH Patched 7.1 2026-08-05 IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function fo…
CVE-2026-9080 HIGH Patched 7.3 2026-07-03 Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using …
CVE-2026-9077 HIGH Patched 8.5 2026-08-05 IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to …
CVE-2026-9076 HIGH Patched 7.5 2026-06-09 Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a…