Search
9,841 CVEs
CVEs (9,841, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 176–200 of 9,841 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54067 | CRITICAL | Patched | 9.9 | 2026-06-24 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> breaks out of its surrounding <style> tag when renderSni… |
| CVE-2026-54158 | CRITICAL | Patched | 9.9 | 2026-06-24 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolates cell content raw in f… |
| CVE-2026-50551 | CRITICAL | Patched | 9.9 | 2026-06-24 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute View (data… |
| CVE-2026-52806 | CRITICAL | Patched | 9.9 | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull req… |
| CVE-2026-56165 | CRITICAL | 9.8 | 2026-07-24 | Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. | |
| CVE-2026-15981 | CRITICAL | 9.8 | 2026-07-23 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_vali… | |
| CVE-2026-63359 | CRITICAL | 9.8 | 2026-07-23 | The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass … | |
| CVE-2026-65700 | CRITICAL | 9.8 | 2026-07-23 | h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbi… | |
| CVE-2026-65688 | CRITICAL | Patched | 9.8 | 2026-07-23 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attac… |
| CVE-2026-65689 | CRITICAL | Patched | 9.8 | 2026-07-23 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated att… |
| CVE-2026-65687 | CRITICAL | Patched | 9.8 | 2026-07-23 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attack… |
| CVE-2026-61951 | CRITICAL | 9.8 | 2026-07-23 | Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions. | |
| CVE-2026-59544 | CRITICAL | 9.8 | 2026-07-23 | Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions. | |
| CVE-2026-59540 | CRITICAL | 9.8 | 2026-07-23 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. | |
| CVE-2026-15015 | CRITICAL | 9.8 | 2026-07-23 | The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugi… | |
| CVE-2026-14282 | CRITICAL | 9.8 | 2026-07-23 | The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in… | |
| CVE-2026-15011 | CRITICAL | 9.8 | 2026-07-23 | The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due … | |
| CVE-2026-60372 | CRITICAL | 9.8 | 2026-07-22 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a… | |
| CVE-2026-60367 | CRITICAL | 9.8 | 2026-07-22 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a… | |
| CVE-2026-16606 | CRITICAL | 9.8 | 2026-07-22 | A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-aut… | |
| CVE-2026-2395 | CRITICAL | 9.8 | 2026-07-22 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL … | |
| CVE-2026-61245 | CRITICAL | 9.8 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. … | |
| CVE-2026-61233 | CRITICAL | 9.8 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1.… | |
| CVE-2026-61196 | CRITICAL | 9.8 | 2026-07-21 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.… | |
| CVE-2026-61183 | CRITICAL | 9.8 | 2026-07-21 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Reporting). The supported version that is affected i… |