Search
140,231 CVEs · High severity
EOL hidden · Show all products
CVEs (140,231, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 140,231 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-18329 | HIGH | 8.2 | 2026-09-02 | Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception i… | |
| CVE-2026-18058 | HIGH | 7.5 | 2026-09-02 | The mobile Smart Connect dashboard UI was subject to manipulation by 3rd party apps. When paired with a phishing attack, this manipulation could result in escalated privile… | |
| CVE-2026-14199 | HIGH | 7.1 | 2026-09-02 | Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concaten… | |
| CVE-2026-78604 | HIGH | Patched | 7.8 | 2026-09-02 | Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems… |
| CVE-2026-78590 | HIGH | Patched | 7.3 | 2026-09-02 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged reso… |
| CVE-2025-15485 | HIGH | 8.2 | 2026-09-02 | The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the … | |
| CVE-2026-76782 | HIGH | 7.3 | 2026-09-02 | Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*. | |
| CVE-2026-76759 | HIGH | 7.3 | 2026-09-02 | Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*. | |
| CVE-2026-84801 | HIGH | Patched | 8.8 | 2026-09-02 | Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to min… |
| CVE-2026-84800 | HIGH | Patched | 7.1 | 2026-09-02 | Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId an… |
| CVE-2026-84798 | HIGH | 7.1 | 2026-09-02 | Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsController::actionDeleteForSite(). The method loads an element w… | |
| CVE-2026-84796 | HIGH | Patched | 8.8 | 2026-09-02 | Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepar… |
| CVE-2026-84794 | HIGH | Patched | 7.1 | 2026-09-02 | Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions c… |
| CVE-2026-84770 | HIGH | 8.8 | 2026-09-02 | Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions. | |
| CVE-2026-84764 | HIGH | 8.8 | 2026-09-02 | Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions. | |
| CVE-2026-84759 | HIGH | 7.1 | 2026-09-02 | Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions. | |
| CVE-2026-81775 | HIGH | 7.1 | 2026-09-02 | Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions. | |
| CVE-2026-81774 | HIGH | 7.5 | 2026-09-02 | Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions. | |
| CVE-2026-81772 | HIGH | 8.8 | 2026-09-02 | Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions. | |
| CVE-2026-81771 | HIGH | 7.1 | 2026-09-02 | Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions. | |
| CVE-2026-81770 | HIGH | 7.1 | 2026-09-02 | Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions. | |
| CVE-2026-81769 | HIGH | 8.8 | 2026-09-02 | Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1. | |
| CVE-2026-81289 | HIGH | 7.1 | 2026-09-02 | Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions. | |
| CVE-2026-81288 | HIGH | 7.1 | 2026-09-02 | Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions. | |
| CVE-2026-81283 | HIGH | 8.8 | 2026-09-02 | Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions. |