Search
4,825 CVEs · High severity
CVEs (4,825, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 4,825 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-19219 | HIGH | 8.1 | 2026-09-02 | In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attac… | |
| CVE-2026-18672 | HIGH | 7.5 | 2026-09-02 | In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is … | |
| CVE-2026-75528 | HIGH | 7.2 | 2026-09-02 | The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author URL / Link Log in all versions up to, and including, 2.4.13 due… | |
| CVE-2026-14828 | HIGH | Patched | 8.8 | 2026-09-02 | Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticat… |
| CVE-2026-82883 | HIGH | 7.1 | 2026-09-02 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS. This issue affects Login… | |
| CVE-2026-82183 | HIGH | Patched | 8.1 | 2026-09-02 | The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers… |
| CVE-2026-81807 | HIGH | Patched | 8.8 | 2026-09-02 | The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML att… |
| CVE-2026-81737 | HIGH | Patched | 8.8 | 2026-09-02 | The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing it and outputting it in an admin … |
| CVE-2026-80467 | HIGH | Patched | 8.1 | 2026-09-02 | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually of… |
| CVE-2026-77792 | HIGH | Patched | 7.5 | 2026-09-02 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field value before outputting it in an HTML attribute on an administrative page, … |
| CVE-2026-19723 | HIGH | Patched | 7.1 | 2026-09-02 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in… |
| CVE-2026-19453 | HIGH | Patched | 7.1 | 2026-09-02 | The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting it admini… |
| CVE-2026-19116 | HIGH | Patched | 8.8 | 2026-09-02 | The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend edit… |
| CVE-2026-14357 | HIGH | 8.8 | 2026-09-02 | The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing no… | |
| CVE-2026-12865 | HIGH | Patched | 7.1 | 2026-09-02 | The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before reflecting them into input-attribute values on its admin pages (one… |
| CVE-2026-12526 | HIGH | Patched | 8.1 | 2026-09-02 | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user a… |
| CVE-2025-46418 | HIGH | 7.6 | 2026-09-02 | Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition. | |
| CVE-2024-35585 | HIGH | Patched | 8.6 | 2026-09-02 | Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication. |
| CVE-2026-84441 | HIGH | 7.3 | 2026-09-02 | A security vulnerability has been detected in Piwigo up to 16.3.0. Affected by this issue is some unknown functionality of the file i.php of the component Image Derivative … | |
| CVE-2026-14982 | HIGH | 8.1 | 2026-09-02 | The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This mak… | |
| CVE-2026-14957 | HIGH | 7.5 | 2026-09-02 | In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL w… | |
| CVE-2026-84715 | HIGH | Patched | 8.8 | 2026-09-02 | FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permi… |
| CVE-2026-84485 | HIGH | 7.5 | 2026-09-02 | APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, … | |
| CVE-2026-84484 | HIGH | Patched | 7.5 | 2026-09-02 | ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending … |
| CVE-2026-84702 | HIGH | 7.5 | 2026-09-02 | facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply travers… |