Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

674 CVEs · High severity

CVEs (674, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 451–475 of 674 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-18329 HIGH 8.2 2026-09-02 Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception i…
CVE-2026-18058 HIGH 7.5 2026-09-02 The mobile Smart Connect dashboard UI was subject to manipulation by 3rd party apps. When paired with a phishing attack, this manipulation could result in escalated privile…
CVE-2026-14199 HIGH 7.1 2026-09-02 Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concaten…
CVE-2026-78604 HIGH Patched 7.8 2026-09-02 Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems…
CVE-2026-78590 HIGH Patched 7.3 2026-09-02 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged reso…
CVE-2025-15485 HIGH 8.2 2026-09-02 The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the …
CVE-2026-76782 HIGH 7.3 2026-09-02 Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
CVE-2026-76759 HIGH 7.3 2026-09-02 Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
CVE-2026-84801 HIGH Patched 8.8 2026-09-02 Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to min…
CVE-2026-84800 HIGH Patched 7.1 2026-09-02 Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId an&hellip;
CVE-2026-84798 HIGH 7.1 2026-09-02 Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsController::actionDeleteForSite(). The method loads an element w&hellip;
CVE-2026-84796 HIGH Patched 8.8 2026-09-02 Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepar&hellip;
CVE-2026-84794 HIGH Patched 7.1 2026-09-02 Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions c&hellip;
CVE-2026-84770 HIGH 8.8 2026-09-02 Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.
CVE-2026-84764 HIGH 8.8 2026-09-02 Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.
CVE-2026-84759 HIGH 7.1 2026-09-02 Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.
CVE-2026-81775 HIGH 7.1 2026-09-02 Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions.
CVE-2026-81774 HIGH 7.5 2026-09-02 Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions.
CVE-2026-81772 HIGH 8.8 2026-09-02 Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.
CVE-2026-81771 HIGH 7.1 2026-09-02 Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions.
CVE-2026-81770 HIGH 7.1 2026-09-02 Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions.
CVE-2026-81769 HIGH 8.8 2026-09-02 Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1.
CVE-2026-81289 HIGH 7.1 2026-09-02 Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions.
CVE-2026-81288 HIGH 7.1 2026-09-02 Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions.
CVE-2026-81283 HIGH 8.8 2026-09-02 Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.