Search
133,513 CVEs · High severity
CVEs (133,513, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 133,513 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8426 | HIGH | Patched | 8.8 | 2026-05-21 | Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepare_remote_upgrade/<remoteMPID>. An attacker who cont… |
| CVE-2026-8421 | HIGH | Patched | 8.8 | 2026-05-21 | Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/single_page/dashboard/extend/install.php. An attacker wh… |
| CVE-2026-8417 | HIGH | Patched | 8.8 | 2026-05-21 | Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/do_update/<pkgHandle>. The do_update() method in concrete… |
| CVE-2026-8416 | HIGH | Patched | 8.8 | 2026-05-21 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id). The Concrete CMS security team g… |
| CVE-2026-8415 | HIGH | Patched | 8.8 | 2026-05-21 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder. The Concrete CMS security team ga… |
| CVE-2026-8414 | HIGH | Patched | 8.8 | 2026-05-21 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate. The Concrete CMS security team gave this vuln… |
| CVE-2026-8413 | HIGH | Patched | 8.8 | 2026-05-21 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS security team gave this vul… |
| CVE-2026-8412 | HIGH | Patched | 8.8 | 2026-05-21 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache. The Concrete CMS security team gave this vul… |
| CVE-2026-8411 | HIGH | Patched | 8.8 | 2026-05-21 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS security team gave this vul… |
| CVE-2026-8410 | HIGH | Patched | 8.8 | 2026-05-21 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete. The The Concrete CMS security team gave thi… |
| CVE-2026-8409 | HIGH | Patched | 8.8 | 2026-05-21 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete. The The Concrete CMS security team gave this vul… |
| CVE-2026-8396 | HIGH | Patched | 7.5 | 2026-07-17 | Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Data External Linking. This issue affects NetGIS: from… |
| CVE-2026-8390 | HIGH | Patched | 7.3 | 2026-05-12 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3. |
| CVE-2026-8389 | HIGH | Patched | 8.8 | 2026-05-12 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3. |
| CVE-2026-8379 | HIGH | 7.5 | 2026-06-23 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file download handler, allowing unauthenticated attackers to… | |
| CVE-2026-8377 | HIGH | 8.2 | 2026-07-07 | Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Collect Data from Common Resource Locations. This issue … | |
| CVE-2026-8365 | HIGH | 8.8 | 2026-06-09 | The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_meta' REST API field and the V200 database migration… | |
| CVE-2026-8361 | HIGH | 7.5 | 2026-05-27 | A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome | |
| CVE-2026-8360 | HIGH | 7.5 | 2026-05-27 | Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWebDavModule.dll) can return a NULL pointer (i.e., whe… | |
| CVE-2026-8359 | HIGH | 7.5 | 2026-05-27 | When processing a request with a URL path starting with /status or /sysinfo, WOSHttpStatusModule.dll is to be loaded to handle such URL patterns. The WOSBin_LoadHttpModule … | |
| CVE-2026-8357 | HIGH | 7.8 | 2026-06-15 | LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The ar… | |
| CVE-2026-8350 | HIGH | Patched | 8.8 | 2026-05-21 | Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Administrative Group. Any auth… |
| CVE-2026-8336 | HIGH | Patched | 7.5 | 2026-05-13 | After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in a certain way, an authenticated user can subsequent… |
| CVE-2026-8321 | HIGH | 7.3 | 2026-05-11 | A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the file agents-api/src/middleware/runAuth.ts of the comp… | |
| CVE-2026-8314 | HIGH | Patched | 7.3 | 2026-07-14 | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. The vulnerability stems from improper validati… |