Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

140,640 CVEs · High severity

CVEs (140,640, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 276–300 of 140,640 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-84428 HIGH Patched 7.5 2026-09-04 fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the trans…
CVE-2026-85540 HIGH 8.8 2026-09-04 DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.
CVE-2026-84504 HIGH Patched 8.1 2026-09-04 fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If a request t…
CVE-2026-84469 HIGH Patched 7.5 2026-09-04 fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines the boolean false as a valid schem…
CVE-2026-76169 HIGH Patched 7.5 2026-09-04 fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke…
CVE-2026-85525 HIGH 7.4 2026-09-04 Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses w…
CVE-2026-81665 HIGH 7.5 2026-09-04 A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to rea…
CVE-2026-81302 HIGH 7.8 2026-09-04 PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM privileges on the affe…
CVE-2026-57777 HIGH Patched 7.6 2026-09-04 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooCommerce allows Blind SQL Injection. This issue affects…
CVE-2026-85197 HIGH 7.6 2026-09-04 A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implement…
CVE-2026-85094 HIGH Patched 8.8 2026-09-04 The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebVie…
CVE-2026-81270 HIGH Patched 7.5 2026-09-04 Apache Allura: exposure of non-public information via search. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, wh…
CVE-2026-66840 HIGH 7.5 2026-09-04 XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked.
CVE-2026-19224 HIGH Patched 7.2 2026-09-04 The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site…
CVE-2026-16281 HIGH Patched 7.1 2026-09-04 The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or…
CVE-2026-85505 HIGH Patched 7.5 2026-09-04 ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short…
CVE-2026-85403 HIGH 7.3 2026-09-04 A flaw has been found in code-projects Doctor Appointment System 1.0. This issue affects some unknown processing of the file /contactus.php. This manipulation of the argume…
CVE-2026-85402 HIGH 7.3 2026-09-04 A vulnerability was detected in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient/booking.php. The manipulation of t…
CVE-2026-85399 HIGH 7.3 2026-09-04 A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the function getSinglePresp of the file includes/pre…
CVE-2026-85398 HIGH 7.3 2026-09-04 A vulnerability was identified in code-projects Hospital Information System 1.0. Affected is the function viewReq of the file viewReq.php. Such manipulation of the argument…
CVE-2026-85147 HIGH 7.5 2026-09-04 SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the s…
CVE-2026-85397 HIGH 7.3 2026-09-04 A vulnerability was determined in code-projects Hospital Information System 1.0. This impacts the function findBySearch of the file addReq.php. This manipulation of the arg…
CVE-2026-45200 HIGH 7.8 2026-09-04 Software installed and run as a non-privileged user may conduct improper GPU driver IOCTL calls to create an allocation scenario that when freed would cause double free and…
CVE-2026-85380 HIGH 7.3 2026-09-04 A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This vulnerability affects the function c…
CVE-2026-85379 HIGH 7.3 2026-09-04 A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects the function ChapterMod…