Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

9,841 CVEs

CVEs (9,841, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 176–200 of 9,841 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-54067 CRITICAL Patched 9.9 2026-06-24 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> breaks out of its surrounding <style> tag when renderSni&hellip;
CVE-2026-54158 CRITICAL Patched 9.9 2026-06-24 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolates cell content raw in f&hellip;
CVE-2026-50551 CRITICAL Patched 9.9 2026-06-24 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute View (data&hellip;
CVE-2026-52806 CRITICAL Patched 9.9 2026-06-24 Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull req&hellip;
CVE-2026-56165 CRITICAL 9.8 2026-07-24 Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
CVE-2026-15981 CRITICAL 9.8 2026-07-23 The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_vali&hellip;
CVE-2026-63359 CRITICAL 9.8 2026-07-23 The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass &hellip;
CVE-2026-65700 CRITICAL 9.8 2026-07-23 h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbi&hellip;
CVE-2026-65688 CRITICAL Patched 9.8 2026-07-23 Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attac&hellip;
CVE-2026-65689 CRITICAL Patched 9.8 2026-07-23 Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated att&hellip;
CVE-2026-65687 CRITICAL Patched 9.8 2026-07-23 Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attack&hellip;
CVE-2026-61951 CRITICAL 9.8 2026-07-23 Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
CVE-2026-59544 CRITICAL 9.8 2026-07-23 Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
CVE-2026-59540 CRITICAL 9.8 2026-07-23 Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.
CVE-2026-15015 CRITICAL 9.8 2026-07-23 The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugi&hellip;
CVE-2026-14282 CRITICAL 9.8 2026-07-23 The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in&hellip;
CVE-2026-15011 CRITICAL 9.8 2026-07-23 The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due &hellip;
CVE-2026-60372 CRITICAL 9.8 2026-07-22 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a&hellip;
CVE-2026-60367 CRITICAL 9.8 2026-07-22 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a&hellip;
CVE-2026-16606 CRITICAL 9.8 2026-07-22 A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-aut&hellip;
CVE-2026-2395 CRITICAL 9.8 2026-07-22 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL &hellip;
CVE-2026-61245 CRITICAL 9.8 2026-07-21 Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. &hellip;
CVE-2026-61233 CRITICAL 9.8 2026-07-21 Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1.&hellip;
CVE-2026-61196 CRITICAL 9.8 2026-07-21 Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.&hellip;
CVE-2026-61183 CRITICAL 9.8 2026-07-21 Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Reporting). The supported version that is affected i&hellip;