Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

11,582 CVEs · High severity

CVEs (11,582, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 376–400 of 11,582 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-81300 HIGH 7.1 2026-09-03 Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions.
CVE-2026-81295 HIGH 7.1 2026-09-03 Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions.
CVE-2026-81292 HIGH 7.1 2026-09-03 Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions.
CVE-2026-85138 HIGH 7.3 2026-09-03 A vulnerability was detected in SeaCMS up to 13.6. Affected is the function addslashes of the file weixin/index.php of the component WeChat Module. The manipulation of the &hellip;
CVE-2026-85137 HIGH 7.3 2026-09-03 A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. The m&hellip;
CVE-2026-83961 HIGH 7.1 2026-09-03 ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain limited &hellip;
CVE-2026-75035 HIGH Patched 7.7 2026-09-03 A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its intern&hellip;
CVE-2026-75034 HIGH Patched 7.4 2026-09-03 A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, s&hellip;
CVE-2026-71963 HIGH Patched 8.8 2026-09-03 Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supply&hellip;
CVE-2026-55658 HIGH 7.7 2026-09-03 Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In &hellip;
CVE-2026-48486 HIGH Patched 7.5 2026-09-03 Signum Node is a HDD-mined cryptocurrency using an energy efficient and fair Proof-of-Commitment (PoC+) consensus algorithm. Prior to version 3.9.9, an integer overflow in &hellip;
CVE-2026-85214 HIGH 8.1 2026-09-03 vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in the reque&hellip;
CVE-2026-85213 HIGH 7.6 2026-09-03 Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Auth&hellip;
CVE-2026-85212 HIGH 8.3 2026-09-03 CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrat&hellip;
CVE-2026-85211 HIGH 7.7 2026-09-03 Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud sto&hellip;
CVE-2026-85182 HIGH 7.5 2026-09-03 vhr through commit 03abbd3 fails to verify that the account ID in PUT /hr/pass requests belongs to the authenticated caller. Authenticated attackers can change arbitrary ac&hellip;
CVE-2026-85180 HIGH 7.5 2026-09-03 Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. An attack&hellip;
CVE-2026-85179 HIGH 8.5 2026-09-03 Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud me&hellip;
CVE-2026-85178 HIGH 7.7 2026-09-03 Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the &hellip;
CVE-2026-85176 HIGH 8.8 2026-09-03 DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers&hellip;
CVE-2026-84989 HIGH 7.1 2026-09-03 ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature — `POST /lu&hellip;
CVE-2026-75033 HIGH Patched 7.7 2026-09-03 A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the r&hellip;
CVE-2026-71404 HIGH Patched 8.7 2026-09-03 A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation an&hellip;
CVE-2026-85110 HIGH 8.8 2026-09-03 A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manip&hellip;
CVE-2025-12737 HIGH 8.4 2026-09-03 The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative&hellip;