Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

127,907 CVEs · High severity

CVEs (127,907, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 51–75 of 127,907 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-11462 HIGH 7.3 2026-06-07 A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function callback of the file plugins/Stripe/Controllers/Stripe…
CVE-2026-11460 HIGH 7.3 2026-06-07 A flaw has been found in Boost Serialization up to 1.91. The impacted element is an unknown function. This manipulation causes improper validation of specified type of inpu…
CVE-2026-49494 HIGH 7.5 2026-06-07 Comodo Internet Security's firewall driver Inspect.sys contains an integer underflow in its IPv6 packet parser. The parser decrements an unsigned 64-bit payload-length valu…
CVE-2026-11457 HIGH 7.3 2026-06-07 A security flaw has been discovered in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This vulnerability affects unknown code of the file /base-boot/jmre…
CVE-2026-11456 HIGH 7.3 2026-06-07 A vulnerability was identified in Chanjet CRM 1.0. This affects an unknown part of the file /tools/jxf_dump_systable.php of the component HTTP GET Request Handler. Such man…
CVE-2026-11452 HIGH Patched 7.3 2026-06-07 A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function FUN_0042e200 of the file /cgi-bin/glc of the component SET_USER_PWD Handler. The m…
CVE-2026-11451 HIGH 7.3 2026-06-07 A flaw has been found in GL.iNet GL-MT3000 4.4.5. This impacts the function snprintf of the file /cgi-bin/glc of the component FTP Protocol Handler. Executing a manipulatio…
CVE-2026-11450 HIGH 7.3 2026-06-07 A vulnerability was detected in GL.iNet GL-MT3000 4.4.5. This affects the function dlopen in the library /usr/lib/oui-httpd/rpc/ of the component Path Normalization Handler…
CVE-2026-26422 HIGH Patched 8.4 2026-06-06 clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, leading to local privilege escalation.
CVE-2026-11437 HIGH 7.3 2026-06-06 A flaw has been found in perfree go-fastdfs-web up to 1.3.7. Affected is the function checkServer of the file /install/checkServer of the component Installation Endpoint. E…
CVE-2026-11435 HIGH 7.3 2026-06-06 A security vulnerability has been detected in Jinher OA 1.0. This affects an unknown function of the file nextselectplan.aspx. Such manipulation of the argument httpOID lea…
CVE-2026-11413 HIGH 8.8 2026-06-06 A security vulnerability has been detected in JingDong JD Cloud Box AX6600 4.5.3.r4546. The impacted element is the function set_macfilter of the file /sbin/jdcweb_rpc. The…
CVE-2026-10725 HIGH 7.5 2026-06-06 Protocol::HTTP2 versions through 1.12 for Perl is vulnerable to a HTTP/2 Bomb. Protocol::HTTP2's inbound HPACK path has no header-list size limit, so a small HTTP/2 reques…
CVE-2026-9851 HIGH 7.2 2026-06-06 The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capab…
CVE-2026-7537 HIGH 7.2 2026-06-06 The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. T…
CVE-2026-8901 HIGH 7.2 2026-06-06 The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Submi…
CVE-2026-8438 HIGH 7.2 2026-06-06 The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.4.7. This is due …
CVE-2026-9290 HIGH 7.5 2026-06-06 The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (pro…
CVE-2026-7654 HIGH 8.8 2026-06-05 The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.18. This is due to the use…
CVE-2026-11416 HIGH 8.1 2026-06-05 MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where the local destination path is constructed by concat…
CVE-2026-36785 HIGH 7.5 2026-06-05 Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the page parameter of the fromDhcpListClient function. This vulnerabil…
CVE-2026-11422 HIGH 7.1 2026-06-05 Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom rendering pipeline that allows attackers to execute arb…
CVE-2026-46493 HIGH 7.5 2026-06-05 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `uniqid` for generating salts, which is unsuitable. Version 26.0.1 fixes t…
CVE-2026-45300 HIGH Patched 7.4 2026-06-05 The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.…
CVE-2026-11401 HIGH Patched 8.0 2026-06-05 An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor…