Search
140,640 CVEs · High severity
CVEs (140,640, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 140,640 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86208 | HIGH | 7.3 | 2026-09-06 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulat… | |
| CVE-2026-8620 | HIGH | Patched | 7.5 | 2026-05-26 | IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulner… |
| CVE-2026-8619 | HIGH | Patched | 7.5 | 2026-08-20 | An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of e… |
| CVE-2026-86188 | HIGH | 7.2 | 2026-09-05 | AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browse… | |
| CVE-2026-86185 | HIGH | 8.0 | 2026-09-05 | Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attack… | |
| CVE-2026-86180 | HIGH | 7.3 | 2026-09-06 | A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the … | |
| CVE-2026-86177 | HIGH | Patched | 8.8 | 2026-09-05 | Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute … |
| CVE-2026-86173 | HIGH | 7.5 | 2026-09-05 | MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supp… | |
| CVE-2026-86169 | HIGH | 8.8 | 2026-09-05 | Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the sec… | |
| CVE-2026-86168 | HIGH | 7.3 | 2026-09-06 | A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of … | |
| CVE-2026-86166 | HIGH | 8.8 | 2026-09-06 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server… | |
| CVE-2026-86162 | HIGH | 7.3 | 2026-09-06 | A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of … | |
| CVE-2026-86161 | HIGH | 7.3 | 2026-09-06 | A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a… | |
| CVE-2026-86160 | HIGH | 7.3 | 2026-09-06 | A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such mani… | |
| CVE-2026-86159 | HIGH | 7.3 | 2026-09-06 | A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument … | |
| CVE-2026-86145 | HIGH | Patched | 8.2 | 2026-09-05 | PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even t… |
| CVE-2026-86140 | HIGH | Patched | 8.0 | 2026-09-05 | In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow. |
| CVE-2026-86123 | HIGH | 8.7 | 2026-09-05 | SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified… | |
| CVE-2026-86119 | HIGH | 8.6 | 2026-09-05 | Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGI… | |
| CVE-2026-86117 | HIGH | 8.1 | 2026-09-05 | Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address w… | |
| CVE-2026-86098 | HIGH | Patched | 7.4 | 2026-09-04 | ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Att… |
| CVE-2026-86095 | HIGH | 7.8 | 2026-09-04 | Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer withou… | |
| CVE-2026-86091 | HIGH | Patched | 7.1 | 2026-09-04 | ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bin… |
| CVE-2026-86090 | HIGH | Patched | 7.1 | 2026-09-04 | ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST… |
| CVE-2026-8604 | HIGH | 8.8 | 2026-05-19 | In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a mali… |