Search
23,330 CVEs · High severity
CVEs (23,330, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 101–125 of 23,330 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-57370 | HIGH | 7.1 | 2026-07-23 | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions. | |
| CVE-2026-57367 | HIGH | 7.1 | 2026-07-23 | Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions. | |
| CVE-2026-25405 | HIGH | 8.5 | 2026-07-23 | Contributor SQL Injection in eRoom <= 1.7.1 versions. | |
| CVE-2026-24552 | HIGH | 8.5 | 2026-07-23 | Contributor SQL Injection in Create by Mediavine <= 2.5.3 versions. | |
| CVE-2026-64611 | HIGH | 7.5 | 2026-07-23 | A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an emp… | |
| CVE-2026-16745 | HIGH | 8.8 | 2026-07-23 | A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can byp… | |
| CVE-2026-15017 | HIGH | 8.8 | 2026-07-23 | The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks… | |
| CVE-2026-52688 | HIGH | 7.5 | 2026-07-23 | RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation | |
| CVE-2026-16287 | HIGH | Patched | 7.8 | 2026-07-23 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-u… |
| CVE-2024-58330 | HIGH | 7.5 | 2026-07-23 | A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data. | |
| CVE-2024-58023 | HIGH | 8.4 | 2026-07-23 | Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information. | |
| CVE-2026-9713 | HIGH | 7.5 | 2026-07-23 | The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed… | |
| CVE-2026-12421 | HIGH | 7.2 | 2026-07-23 | The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1 due to insufficient in… | |
| CVE-2026-14291 | HIGH | Patched | 7.5 | 2026-07-23 | The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an un… |
| CVE-2026-12082 | HIGH | Patched | 7.5 | 2026-07-23 | The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the perma… |
| CVE-2026-7534 | HIGH | 7.2 | 2026-07-23 | The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions … | |
| CVE-2026-7232 | HIGH | 7.2 | 2026-07-23 | The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due to ins… | |
| CVE-2026-15074 | HIGH | Patched | 7.5 | 2026-07-23 | @fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This is a bypass of the earl… |
| CVE-2026-16632 | HIGH | 7.3 | 2026-07-23 | A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the library lib/facil/http/parsers/websocket_parser.h of th… | |
| CVE-2026-61246 | HIGH | 8.8 | 2026-07-22 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a… | |
| CVE-2026-60455 | HIGH | 8.8 | 2026-07-22 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a… | |
| CVE-2026-60439 | HIGH | 8.8 | 2026-07-22 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a… | |
| CVE-2026-60373 | HIGH | 8.8 | 2026-07-22 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a… | |
| CVE-2026-60371 | HIGH | 8.0 | 2026-07-22 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a… | |
| CVE-2026-60370 | HIGH | 7.5 | 2026-07-22 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a… |