Search
140,640 CVEs · High severity
CVEs (140,640, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 140,640 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-85028 | HIGH | Patched | 7.8 | 2026-09-03 | Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4… |
| CVE-2026-82302 | HIGH | 8.1 | 2026-09-03 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). | |
| CVE-2026-78583 | HIGH | 8.1 | 2026-09-03 | Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originati… | |
| CVE-2026-33630 | HIGH | Patched | 7.5 | 2026-09-03 | c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's cal… |
| CVE-2026-85187 | HIGH | 7.3 | 2026-09-03 | A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function Order::pupdate of the file /rider/ord… | |
| CVE-2026-85012 | HIGH | Patched | 8.0 | 2026-09-03 | Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.… |
| CVE-2026-83959 | HIGH | 7.8 | 2026-09-03 | Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitati… | |
| CVE-2026-63219 | HIGH | Patched | 8.6 | 2026-09-03 | GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file up… |
| CVE-2026-84848 | HIGH | 7.1 | 2026-09-03 | Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions. | |
| CVE-2026-84847 | HIGH | 7.5 | 2026-09-03 | Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions. | |
| CVE-2026-84836 | HIGH | 7.1 | 2026-09-03 | Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions. | |
| CVE-2026-84812 | HIGH | 7.1 | 2026-09-03 | Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions. | |
| CVE-2026-84779 | HIGH | 8.1 | 2026-09-03 | Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt & MCP for AI Agents <= 1.51.0 versions. | |
| CVE-2026-84778 | HIGH | 7.5 | 2026-09-03 | Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration & Cloning <= 6.65 versions. | |
| CVE-2026-84777 | HIGH | 7.4 | 2026-09-03 | Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions. | |
| CVE-2026-84776 | HIGH | 7.5 | 2026-09-03 | Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions. | |
| CVE-2026-84773 | HIGH | 7.2 | 2026-09-03 | Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions. | |
| CVE-2026-84765 | HIGH | 7.1 | 2026-09-03 | Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5.1 versions. | |
| CVE-2026-84763 | HIGH | 7.1 | 2026-09-03 | Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions. | |
| CVE-2026-84761 | HIGH | 7.2 | 2026-09-03 | Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions. | |
| CVE-2026-84757 | HIGH | 8.2 | 2026-09-03 | Unauthenticated Settings Change in WP Compress <= 7.21.28 versions. | |
| CVE-2026-84756 | HIGH | 7.1 | 2026-09-03 | Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions. | |
| CVE-2026-84752 | HIGH | 8.8 | 2026-09-03 | Contributor PHP Object Injection in RTMKit <= 2.1.5 versions. | |
| CVE-2026-81776 | HIGH | 7.1 | 2026-09-03 | Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions. | |
| CVE-2026-81773 | HIGH | 7.1 | 2026-09-03 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions. |