Search
140,640 CVEs · High severity
CVEs (140,640, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 140,640 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8695 | HIGH | Patched | 7.5 | 2026-05-15 | radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThr… |
| CVE-2026-8686 | HIGH | Patched | 7.5 | 2026-05-15 | Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet. To re… |
| CVE-2026-8679 | HIGH | 7.5 | 2026-05-22 | The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the handle_playlist_endpoint… | |
| CVE-2026-8676 | HIGH | 8.8 | 2026-05-26 | An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a new bond. | |
| CVE-2026-86713 | HIGH | 7.1 | 2026-09-08 | PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module's stop path where exit_and_cleanup() deletes the LoadMon object and frees the pe… | |
| CVE-2026-86712 | HIGH | Patched | 8.8 | 2026-09-08 | SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled de… |
| CVE-2026-86711 | HIGH | Patched | 7.4 | 2026-09-08 | electerm before 5.3.15 exposes 40+ main-process functions through an unvalidated Electron IPC handler with no function-name allowlist or sender validation. Renderer-side sc… |
| CVE-2026-8671 | HIGH | Patched | 7.5 | 2026-05-22 | Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows Resource Leak Exposure. This issue affects Avantra: … |
| CVE-2026-86665 | HIGH | 7.3 | 2026-09-08 | A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::index of the file controllers/update.php. The manipulation lea… | |
| CVE-2026-8666 | HIGH | Patched | 7.7 | 2026-06-25 | OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via… |
| CVE-2026-8665 | HIGH | Patched | 7.7 | 2026-06-25 | OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text… |
| CVE-2026-8660 | HIGH | Patched | 7.7 | 2026-06-25 | OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host pa… |
| CVE-2026-8657 | HIGH | Patched | 8.2 | 2026-05-16 | Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() and jsondiffpatch/formatters/jsonpatch.patch() APIs. … |
| CVE-2026-86544 | HIGH | Patched | 8.1 | 2026-09-07 | knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with r… |
| CVE-2026-86541 | HIGH | Patched | 8.3 | 2026-09-07 | knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the proj… |
| CVE-2026-86540 | HIGH | Patched | 7.8 | 2026-09-07 | knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by c… |
| CVE-2026-86539 | HIGH | 7.2 | 2026-09-07 | knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied … | |
| CVE-2026-86538 | HIGH | Patched | 7.5 | 2026-09-07 | knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary fil… |
| CVE-2026-86504 | HIGH | Patched | 7.8 | 2026-09-07 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution |
| CVE-2026-86502 | HIGH | Patched | 8.4 | 2026-09-07 | In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts |
| CVE-2026-86498 | HIGH | Patched | 7.7 | 2026-09-07 | In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission |
| CVE-2026-86494 | HIGH | Patched | 7.7 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues |
| CVE-2026-86492 | HIGH | Patched | 8.5 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens |
| CVE-2026-86482 | HIGH | Patched | 8.8 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation |
| CVE-2026-86479 | HIGH | Patched | 8.1 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR |