Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

140,640 CVEs · High severity

CVEs (140,640, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 476–500 of 140,640 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-86208 HIGH 7.3 2026-09-06 A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulat…
CVE-2026-8620 HIGH Patched 7.5 2026-05-26 IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulner…
CVE-2026-8619 HIGH Patched 7.5 2026-08-20 An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of e…
CVE-2026-86188 HIGH 7.2 2026-09-05 AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browse…
CVE-2026-86185 HIGH 8.0 2026-09-05 Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attack…
CVE-2026-86180 HIGH 7.3 2026-09-06 A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the …
CVE-2026-86177 HIGH Patched 8.8 2026-09-05 Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute …
CVE-2026-86173 HIGH 7.5 2026-09-05 MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supp…
CVE-2026-86169 HIGH 8.8 2026-09-05 Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the sec…
CVE-2026-86168 HIGH 7.3 2026-09-06 A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of …
CVE-2026-86166 HIGH 8.8 2026-09-06 A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server…
CVE-2026-86162 HIGH 7.3 2026-09-06 A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of …
CVE-2026-86161 HIGH 7.3 2026-09-06 A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a…
CVE-2026-86160 HIGH 7.3 2026-09-06 A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such mani…
CVE-2026-86159 HIGH 7.3 2026-09-06 A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument …
CVE-2026-86145 HIGH Patched 8.2 2026-09-05 PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even t…
CVE-2026-86140 HIGH Patched 8.0 2026-09-05 In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.
CVE-2026-86123 HIGH 8.7 2026-09-05 SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified…
CVE-2026-86119 HIGH 8.6 2026-09-05 Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGI…
CVE-2026-86117 HIGH 8.1 2026-09-05 Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address w…
CVE-2026-86098 HIGH Patched 7.4 2026-09-04 ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Att…
CVE-2026-86095 HIGH 7.8 2026-09-04 Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer withou…
CVE-2026-86091 HIGH Patched 7.1 2026-09-04 ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bin…
CVE-2026-86090 HIGH Patched 7.1 2026-09-04 ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST…
CVE-2026-8604 HIGH 8.8 2026-05-19 In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a mali…