Search
133,513 CVEs · High severity
CVEs (133,513, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 101–125 of 133,513 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9800 | HIGH | Patched | 8.1 | 2026-06-25 | A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed… |
| CVE-2026-9795 | HIGH | 7.3 | 2026-05-28 | A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can exploit this vulnerability t… | |
| CVE-2026-9787 | HIGH | Patched | 8.8 | 2026-06-25 | Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected … |
| CVE-2026-9786 | HIGH | Patched | 8.8 | 2026-06-25 | Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected inst… |
| CVE-2026-9785 | HIGH | Patched | 8.8 | 2026-06-25 | Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in… |
| CVE-2026-9784 | HIGH | Patched | 8.8 | 2026-06-25 | Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in… |
| CVE-2026-9783 | HIGH | Patched | 8.8 | 2026-06-25 | Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected… |
| CVE-2026-9782 | HIGH | Patched | 8.8 | 2026-06-25 | Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in… |
| CVE-2026-9781 | HIGH | Patched | 8.8 | 2026-06-25 | Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected inst… |
| CVE-2026-9780 | HIGH | Patched | 8.8 | 2026-06-25 | Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected i… |
| CVE-2026-9779 | HIGH | Patched | 7.2 | 2026-06-24 | ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execu… |
| CVE-2026-9778 | HIGH | Patched | 7.2 | 2026-06-24 | ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected insta… |
| CVE-2026-9777 | HIGH | Patched | 7.2 | 2026-06-24 | ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installation… |
| CVE-2026-9776 | HIGH | Patched | 7.5 | 2026-06-24 | ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive inform… |
| CVE-2026-9773 | HIGH | Patched | 8.8 | 2026-06-24 | Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal… |
| CVE-2026-9772 | HIGH | Patched | 8.8 | 2026-06-24 | Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install… |
| CVE-2026-9762 | HIGH | 7.8 | 2026-07-17 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control. | |
| CVE-2026-9758 | HIGH | 7.3 | 2026-06-10 | Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to be considered trusted | |
| CVE-2026-9757 | HIGH | 7.5 | 2026-05-30 | The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlatlng' and 'nelatlng' parameters in all versions up to, and including, 4.5.5 The parameters ar… | |
| CVE-2026-9753 | HIGH | Patched | 8.1 | 2026-06-09 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash … |
| CVE-2026-9742 | HIGH | Patched | 7.5 | 2026-06-09 | When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. … |
| CVE-2026-9740 | HIGH | Patched | 7.5 | 2026-06-09 | A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON valida… |
| CVE-2026-9717 | HIGH | Patched | 7.2 | 2026-06-25 | CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with eleva… |
| CVE-2026-9716 | HIGH | Patched | 7.5 | 2026-06-25 | CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable… |
| CVE-2026-9713 | HIGH | 7.5 | 2026-07-23 | The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed… |