Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

140,640 CVEs · High severity

CVEs (140,640, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 401–425 of 140,640 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-8695 HIGH Patched 7.5 2026-05-15 radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThr…
CVE-2026-8686 HIGH Patched 7.5 2026-05-15 Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet. To re…
CVE-2026-8679 HIGH 7.5 2026-05-22 The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the handle_playlist_endpoint…
CVE-2026-8676 HIGH 8.8 2026-05-26 An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a new bond.
CVE-2026-86713 HIGH 7.1 2026-09-08 PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module's stop path where exit_and_cleanup() deletes the LoadMon object and frees the pe…
CVE-2026-86712 HIGH Patched 8.8 2026-09-08 SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled de…
CVE-2026-86711 HIGH Patched 7.4 2026-09-08 electerm before 5.3.15 exposes 40+ main-process functions through an unvalidated Electron IPC handler with no function-name allowlist or sender validation. Renderer-side sc…
CVE-2026-8671 HIGH Patched 7.5 2026-05-22 Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows Resource Leak Exposure. This issue affects Avantra: …
CVE-2026-86665 HIGH 7.3 2026-09-08 A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::index of the file controllers/update.php. The manipulation lea…
CVE-2026-8666 HIGH Patched 7.7 2026-06-25 OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via…
CVE-2026-8665 HIGH Patched 7.7 2026-06-25 OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text…
CVE-2026-8660 HIGH Patched 7.7 2026-06-25 OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host pa…
CVE-2026-8657 HIGH Patched 8.2 2026-05-16 Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() and jsondiffpatch/formatters/jsonpatch.patch() APIs. …
CVE-2026-86544 HIGH Patched 8.1 2026-09-07 knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with r…
CVE-2026-86541 HIGH Patched 8.3 2026-09-07 knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the proj…
CVE-2026-86540 HIGH Patched 7.8 2026-09-07 knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by c…
CVE-2026-86539 HIGH 7.2 2026-09-07 knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied …
CVE-2026-86538 HIGH Patched 7.5 2026-09-07 knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary fil…
CVE-2026-86504 HIGH Patched 7.8 2026-09-07 In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution
CVE-2026-86502 HIGH Patched 8.4 2026-09-07 In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts
CVE-2026-86498 HIGH Patched 7.7 2026-09-07 In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission
CVE-2026-86494 HIGH Patched 7.7 2026-09-07 In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues
CVE-2026-86492 HIGH Patched 8.5 2026-09-07 In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens
CVE-2026-86482 HIGH Patched 8.8 2026-09-07 In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation
CVE-2026-86479 HIGH Patched 8.1 2026-09-07 In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR