Search
140,640 CVEs · High severity
CVEs (140,640, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 301–325 of 140,640 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9072 | HIGH | Patched | 8.1 | 2026-06-22 | IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulne… |
| CVE-2026-9071 | HIGH | Patched | 7.5 | 2026-06-22 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by send… |
| CVE-2026-9064 | HIGH | 7.5 | 2026-05-20 | A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. … | |
| CVE-2026-9057 | HIGH | Patched | 8.2 | 2026-05-20 | A broken access control issue has been identified in the Talend Administration Center, that allows a user with “View” permission to modify the Talend Studio update URL. Thi… |
| CVE-2026-9047 | HIGH | Patched | 7.6 | 2026-05-22 | Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to … |
| CVE-2026-9046 | HIGH | 7.0 | 2026-07-16 | A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, tha… | |
| CVE-2026-9045 | HIGH | 7.8 | 2026-06-10 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a loc… | |
| CVE-2026-9044 | HIGH | Patched | 8.0 | 2026-07-31 | An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitra… |
| CVE-2026-9029 | HIGH | 7.3 | 2026-06-22 | A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in… | |
| CVE-2026-9024 | HIGH | 8.7 | 2026-06-01 | A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3D… | |
| CVE-2026-9018 | HIGH | 8.8 | 2026-05-22 | The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the … | |
| CVE-2026-9011 | HIGH | 7.5 | 2026-05-22 | The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.65. This is due… | |
| CVE-2026-9010 | HIGH | 7.5 | 2026-05-20 | The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and including, 2.0.3 due to ins… | |
| CVE-2026-9009 | HIGH | 8.8 | 2026-05-28 | The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.7.2 via the filter_cont… | |
| CVE-2026-9006 | HIGH | Patched | 7.4 | 2026-06-22 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unautho… |
| CVE-2026-9003 | HIGH | 7.5 | 2026-05-20 | E-LAN Hybrid Recording System developed by TONNET has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read data… | |
| CVE-2026-8994 | HIGH | 8.1 | 2026-05-27 | The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.3.3. The `ajaxLoginWithNear()` function — registered… | |
| CVE-2026-8992 | HIGH | Patched | 8.8 | 2026-05-22 | An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code. |
| CVE-2026-8987 | HIGH | Patched | 8.8 | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated at… |
| CVE-2026-8982 | HIGH | Patched | 8.1 | 2026-07-21 | Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on d… |
| CVE-2026-8975 | HIGH | Patched | 8.8 | 2026-05-19 | Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enoug… |
| CVE-2026-8974 | HIGH | Patched | 8.8 | 2026-05-19 | Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the… |
| CVE-2026-8973 | HIGH | Patched | 8.8 | 2026-05-19 | Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl… |
| CVE-2026-8972 | HIGH | Patched | 8.8 | 2026-05-19 | Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
| CVE-2026-8970 | HIGH | Patched | 8.8 | 2026-05-19 | Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. |