Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

140,640 CVEs · High severity

CVEs (140,640, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 301–325 of 140,640 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9072 HIGH Patched 8.1 2026-06-22 IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulne…
CVE-2026-9071 HIGH Patched 7.5 2026-06-22 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by send…
CVE-2026-9064 HIGH 7.5 2026-05-20 A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. …
CVE-2026-9057 HIGH Patched 8.2 2026-05-20 A broken access control issue has been identified in the Talend Administration Center, that allows a user with “View” permission to modify the Talend Studio update URL. Thi…
CVE-2026-9047 HIGH Patched 7.6 2026-05-22 Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to …
CVE-2026-9046 HIGH 7.0 2026-07-16 A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, tha…
CVE-2026-9045 HIGH 7.8 2026-06-10 During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a loc…
CVE-2026-9044 HIGH Patched 8.0 2026-07-31 An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitra…
CVE-2026-9029 HIGH 7.3 2026-06-22 A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in…
CVE-2026-9024 HIGH 8.7 2026-06-01 A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3D…
CVE-2026-9018 HIGH 8.8 2026-05-22 The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the …
CVE-2026-9011 HIGH 7.5 2026-05-22 The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.65. This is due…
CVE-2026-9010 HIGH 7.5 2026-05-20 The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and including, 2.0.3 due to ins…
CVE-2026-9009 HIGH 8.8 2026-05-28 The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.7.2 via the filter_cont…
CVE-2026-9006 HIGH Patched 7.4 2026-06-22 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unautho…
CVE-2026-9003 HIGH 7.5 2026-05-20 E-LAN Hybrid Recording System developed by TONNET has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read data…
CVE-2026-8994 HIGH 8.1 2026-05-27 The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.3.3. The `ajaxLoginWithNear()` function — registered…
CVE-2026-8992 HIGH Patched 8.8 2026-05-22 An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.
CVE-2026-8987 HIGH Patched 8.8 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated at…
CVE-2026-8982 HIGH Patched 8.1 2026-07-21 Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on d…
CVE-2026-8975 HIGH Patched 8.8 2026-05-19 Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enoug…
CVE-2026-8974 HIGH Patched 8.8 2026-05-19 Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…
CVE-2026-8973 HIGH Patched 8.8 2026-05-19 Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl…
CVE-2026-8972 HIGH Patched 8.8 2026-05-19 Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
CVE-2026-8970 HIGH Patched 8.8 2026-05-19 Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.