Search
140,640 CVEs · High severity
CVEs (140,640, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 276–300 of 140,640 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-84428 | HIGH | Patched | 7.5 | 2026-09-04 | fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the trans… |
| CVE-2026-85540 | HIGH | 8.8 | 2026-09-04 | DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents. | |
| CVE-2026-84504 | HIGH | Patched | 8.1 | 2026-09-04 | fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If a request t… |
| CVE-2026-84469 | HIGH | Patched | 7.5 | 2026-09-04 | fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines the boolean false as a valid schem… |
| CVE-2026-76169 | HIGH | Patched | 7.5 | 2026-09-04 | fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke… |
| CVE-2026-85525 | HIGH | 7.4 | 2026-09-04 | Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses w… | |
| CVE-2026-81665 | HIGH | 7.5 | 2026-09-04 | A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to rea… | |
| CVE-2026-81302 | HIGH | 7.8 | 2026-09-04 | PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM privileges on the affe… | |
| CVE-2026-57777 | HIGH | Patched | 7.6 | 2026-09-04 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooCommerce allows Blind SQL Injection. This issue affects… |
| CVE-2026-85197 | HIGH | 7.6 | 2026-09-04 | A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implement… | |
| CVE-2026-85094 | HIGH | Patched | 8.8 | 2026-09-04 | The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebVie… |
| CVE-2026-81270 | HIGH | Patched | 7.5 | 2026-09-04 | Apache Allura: exposure of non-public information via search. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, wh… |
| CVE-2026-66840 | HIGH | 7.5 | 2026-09-04 | XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked. | |
| CVE-2026-19224 | HIGH | Patched | 7.2 | 2026-09-04 | The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site… |
| CVE-2026-16281 | HIGH | Patched | 7.1 | 2026-09-04 | The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or… |
| CVE-2026-85505 | HIGH | Patched | 7.5 | 2026-09-04 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short… |
| CVE-2026-85403 | HIGH | 7.3 | 2026-09-04 | A flaw has been found in code-projects Doctor Appointment System 1.0. This issue affects some unknown processing of the file /contactus.php. This manipulation of the argume… | |
| CVE-2026-85402 | HIGH | 7.3 | 2026-09-04 | A vulnerability was detected in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient/booking.php. The manipulation of t… | |
| CVE-2026-85399 | HIGH | 7.3 | 2026-09-04 | A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the function getSinglePresp of the file includes/pre… | |
| CVE-2026-85398 | HIGH | 7.3 | 2026-09-04 | A vulnerability was identified in code-projects Hospital Information System 1.0. Affected is the function viewReq of the file viewReq.php. Such manipulation of the argument… | |
| CVE-2026-85147 | HIGH | 7.5 | 2026-09-04 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the s… | |
| CVE-2026-85397 | HIGH | 7.3 | 2026-09-04 | A vulnerability was determined in code-projects Hospital Information System 1.0. This impacts the function findBySearch of the file addReq.php. This manipulation of the arg… | |
| CVE-2026-45200 | HIGH | 7.8 | 2026-09-04 | Software installed and run as a non-privileged user may conduct improper GPU driver IOCTL calls to create an allocation scenario that when freed would cause double free and… | |
| CVE-2026-85380 | HIGH | 7.3 | 2026-09-04 | A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This vulnerability affects the function c… | |
| CVE-2026-85379 | HIGH | 7.3 | 2026-09-04 | A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects the function ChapterMod… |