Search
140,265 CVEs · High severity
EOL hidden · Show all products
CVEs (140,265, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 176–200 of 140,265 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-52770 | HIGH | Patched | 7.5 | 2026-09-05 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthenticated SQL injection in numeric query … |
| CVE-2026-52769 | HIGH | Patched | 8.3 | 2026-09-05 | YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route - exposed publicly with acl:"public" - a… |
| CVE-2026-52767 | HIGH | Patched | 8.2 | 2026-09-05 | YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() wit… |
| CVE-2026-86098 | HIGH | Patched | 7.4 | 2026-09-04 | ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Att… |
| CVE-2026-86095 | HIGH | 7.8 | 2026-09-04 | Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer withou… | |
| CVE-2026-48019 | HIGH | Patched | 8.9 | 2026-09-04 | Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony… |
| CVE-2026-86091 | HIGH | Patched | 7.1 | 2026-09-04 | ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bin… |
| CVE-2026-86090 | HIGH | Patched | 7.1 | 2026-09-04 | ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST… |
| CVE-2026-82684 | HIGH | 8.1 | 2026-09-04 | Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credential… | |
| CVE-2026-77393 | HIGH | 8.8 | 2026-09-04 | In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute g… | |
| CVE-2026-85702 | HIGH | 7.3 | 2026-09-04 | A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file … | |
| CVE-2026-82712 | HIGH | 8.8 | 2026-09-04 | Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changi… | |
| CVE-2026-79423 | HIGH | 8.8 | 2026-09-04 | An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request. | |
| CVE-2026-75438 | HIGH | 7.5 | 2026-09-04 | Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function | |
| CVE-2026-85786 | HIGH | Patched | 7.5 | 2026-09-04 | Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document… |
| CVE-2026-71626 | HIGH | 7.5 | 2026-09-04 | An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php… | |
| CVE-2026-63464 | HIGH | Patched | 7.7 | 2026-09-04 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: tru… |
| CVE-2026-61699 | HIGH | Patched | 8.1 | 2026-09-04 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarde… |
| CVE-2026-53932 | HIGH | Patched | 8.0 | 2026-09-04 | laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during d… |
| CVE-2026-85781 | HIGH | Patched | 8.7 | 2026-09-04 | Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with… |
| CVE-2026-85638 | HIGH | 7.3 | 2026-09-04 | A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. This manipulation of the argument vId/id causes authorization byp… | |
| CVE-2026-80119 | HIGH | Patched | 7.8 | 2026-09-04 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability i… |
| CVE-2026-80118 | HIGH | Patched | 7.1 | 2026-09-04 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclo… |
| CVE-2026-80117 | HIGH | Patched | 7.1 | 2026-09-04 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in D… |
| CVE-2026-80116 | HIGH | Patched | 7.8 | 2026-09-04 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in D… |