Search
133,513 CVEs · High severity
CVEs (133,513, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 133,513 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8313 | HIGH | Patched | 7.3 | 2026-07-14 | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validat… |
| CVE-2026-8312 | HIGH | Patched | 7.3 | 2026-07-14 | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validati… |
| CVE-2026-8305 | HIGH | Patched | 7.3 | 2026-05-11 | A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookRequest of the file extensions/bluebubbles/src/monito… |
| CVE-2026-8293 | HIGH | Patched | 7.5 | 2026-06-02 | The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing a… |
| CVE-2026-8286 | HIGH | Patched | 8.1 | 2026-07-03 | A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatche… |
| CVE-2026-8260 | HIGH | Patched | 8.8 | 2026-05-11 | A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of the file /web/cgi-bin/hnap/hnap_service of the compone… |
| CVE-2026-8234 | HIGH | 8.8 | 2026-05-10 | A security vulnerability has been detected in EFM ipTIME A8004T 14.18.2. This vulnerability affects the function formWifiBasicSet of the file /goform/WifiBasicSet. The mani… | |
| CVE-2026-8216 | HIGH | 7.3 | 2026-05-10 | A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This issue affects the function iasServerRemoteInterface.doAction of the component Ja… | |
| CVE-2026-8180 | HIGH | Patched | 7.5 | 2026-05-27 | IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Tr… |
| CVE-2026-8179 | HIGH | Patched | 8.8 | 2026-05-27 | IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Tr… |
| CVE-2026-8178 | HIGH | Patched | 8.1 | 2026-05-08 | An issue exists in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load and execute arbitrary classes when processing JDBC c… |
| CVE-2026-8177 | HIGH | 7.5 | 2026-05-10 | XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in th… | |
| CVE-2026-8176 | HIGH | 7.5 | 2026-06-16 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and inclu… | |
| CVE-2026-8172 | HIGH | 7.1 | 2026-06-23 | The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it into the contact form output on validation errors, … | |
| CVE-2026-8163 | HIGH | Patched | 8.8 | 2026-06-23 | The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using them in SQL statements, leading to a SQL Injection vu… |
| CVE-2026-8162 | HIGH | Patched | 7.5 | 2026-05-12 | multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a Content-Disposition header w… |
| CVE-2026-8161 | HIGH | Patched | 7.5 | 2026-05-12 | multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a field name that collides wit… |
| CVE-2026-8159 | HIGH | Patched | 7.5 | 2026-05-12 | multiparty@4.2.3 and lower versions are vulnerable to denial of service via regular expression backtracking in the Content-Disposition filename parameter parser. A crafted … |
| CVE-2026-8157 | HIGH | Patched | 8.8 | 2026-06-22 | The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing aut… |
| CVE-2026-8148 | HIGH | Patched | 7.8 | 2026-05-08 | NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks. |
| CVE-2026-8147 | HIGH | Patched | 8.1 | 2026-07-02 | In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated us… |
| CVE-2026-8143 | HIGH | 7.2 | 2026-05-27 | The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hb_country_iso', 'hb_usa_state_iso', and 'hb_canada_province_iso' parameters in all ver… | |
| CVE-2026-8141 | HIGH | 7.2 | 2026-06-30 | The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include_children' parameter in all versions up to, and incl… | |
| CVE-2026-8138 | HIGH | 8.8 | 2026-05-08 | A vulnerability was found in Tenda CX12L 16.03.53.12. This issue affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg”. The manipulation results in s… | |
| CVE-2026-8137 | HIGH | 8.8 | 2026-05-08 | A vulnerability has been found in Totolink X5000R 9.1.0u.6369_B20230113. This vulnerability affects the function sub_458E40 of the file /boafrm/formDdns. The manipulation o… |