Search
4,825 CVEs · High severity
CVEs (4,825, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 101–125 of 4,825 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-86214 | HIGH | 7.3 | 2026-09-06 | A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument ema… | |
| CVE-2026-86213 | HIGH | 7.3 | 2026-09-06 | A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search H… | |
| CVE-2026-86250 | HIGH | Patched | 7.5 | 2026-09-06 | h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attacke… |
| CVE-2026-86242 | HIGH | Patched | 8.1 | 2026-09-06 | Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is d… |
| CVE-2022-51009 | HIGH | Patched | 7.5 | 2026-09-06 | PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin pack… |
| CVE-2026-86211 | HIGH | 7.3 | 2026-09-06 | A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulati… | |
| CVE-2026-86210 | HIGH | 7.3 | 2026-09-06 | A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /… | |
| CVE-2026-86209 | HIGH | 7.3 | 2026-09-06 | A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_user.php. This manipulation of t… | |
| CVE-2026-86208 | HIGH | 7.3 | 2026-09-06 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulat… | |
| CVE-2026-86180 | HIGH | 7.3 | 2026-09-06 | A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the … | |
| CVE-2026-84219 | HIGH | Patched | 7.5 | 2026-09-06 | The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScrip… |
| CVE-2026-18480 | HIGH | Patched | 8.8 | 2026-09-06 | The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing use… |
| CVE-2026-86168 | HIGH | 7.3 | 2026-09-06 | A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of … | |
| CVE-2026-86166 | HIGH | 8.8 | 2026-09-06 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server… | |
| CVE-2026-86162 | HIGH | 7.3 | 2026-09-06 | A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of … | |
| CVE-2026-86161 | HIGH | 7.3 | 2026-09-06 | A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a… | |
| CVE-2026-86160 | HIGH | 7.3 | 2026-09-06 | A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such mani… | |
| CVE-2026-86159 | HIGH | 7.3 | 2026-09-06 | A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument … | |
| CVE-2026-18056 | HIGH | 7.5 | 2026-09-06 | The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is… | |
| CVE-2026-0799 | HIGH | 8.7 | 2026-09-05 | In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF inter… | |
| CVE-2026-86188 | HIGH | 7.2 | 2026-09-05 | AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browse… | |
| CVE-2026-86185 | HIGH | 8.0 | 2026-09-05 | Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attack… | |
| CVE-2025-9049 | HIGH | 8.8 | 2026-09-05 | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_… | |
| CVE-2026-86177 | HIGH | Patched | 8.8 | 2026-09-05 | Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute … |
| CVE-2026-86173 | HIGH | 7.5 | 2026-09-05 | MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supp… |