Search
140,640 CVEs · High severity
CVEs (140,640, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 140,640 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-81300 | HIGH | 7.1 | 2026-09-03 | Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions. | |
| CVE-2026-81773 | HIGH | 7.1 | 2026-09-03 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | |
| CVE-2026-81776 | HIGH | 7.1 | 2026-09-03 | Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions. | |
| CVE-2026-85137 | HIGH | 7.3 | 2026-09-03 | A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. The m… | |
| CVE-2026-85138 | HIGH | 7.3 | 2026-09-03 | A vulnerability was detected in SeaCMS up to 13.6. Affected is the function addslashes of the file weixin/index.php of the component WeChat Module. The manipulation of the … | |
| CVE-2026-83961 | HIGH | 7.1 | 2026-09-03 | ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain limited … | |
| CVE-2026-75034 | HIGH | Patched | 7.4 | 2026-09-03 | A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, s… |
| CVE-2026-75035 | HIGH | Patched | 7.7 | 2026-09-03 | A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its intern… |
| CVE-2026-71963 | HIGH | Patched | 8.8 | 2026-09-03 | Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supply… |
| CVE-2026-55658 | HIGH | 7.7 | 2026-09-03 | Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In … | |
| CVE-2026-48486 | HIGH | Patched | 7.5 | 2026-09-03 | Signum Node is a HDD-mined cryptocurrency using an energy efficient and fair Proof-of-Commitment (PoC+) consensus algorithm. Prior to version 3.9.9, an integer overflow in … |
| CVE-2026-85211 | HIGH | 7.7 | 2026-09-03 | Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud sto… | |
| CVE-2026-85212 | HIGH | 8.3 | 2026-09-03 | CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrat… | |
| CVE-2026-85213 | HIGH | 7.6 | 2026-09-03 | Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Auth… | |
| CVE-2026-85214 | HIGH | 8.1 | 2026-09-03 | vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in the reque… | |
| CVE-2026-85179 | HIGH | 8.5 | 2026-09-03 | Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud me… | |
| CVE-2026-85180 | HIGH | 7.5 | 2026-09-03 | Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. An attack… | |
| CVE-2026-85182 | HIGH | 7.5 | 2026-09-03 | vhr through commit 03abbd3 fails to verify that the account ID in PUT /hr/pass requests belongs to the authenticated caller. Authenticated attackers can change arbitrary ac… | |
| CVE-2026-85176 | HIGH | 8.8 | 2026-09-03 | DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers… | |
| CVE-2026-85178 | HIGH | 7.7 | 2026-09-03 | Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the … | |
| CVE-2026-84989 | HIGH | 7.1 | 2026-09-03 | ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature — `POST /lu… | |
| CVE-2026-71404 | HIGH | Patched | 8.7 | 2026-09-03 | A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation an… |
| CVE-2026-75033 | HIGH | Patched | 7.7 | 2026-09-03 | A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the r… |
| CVE-2026-85110 | HIGH | 8.8 | 2026-09-03 | A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manip… | |
| CVE-2025-12737 | HIGH | 8.4 | 2026-09-03 | The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative… |