Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

140,640 CVEs · High severity

CVEs (140,640, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 201–225 of 140,640 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-80114 HIGH Patched 7.8 2026-09-04 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in…
CVE-2026-80113 HIGH Patched 7.1 2026-09-04 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in D…
CVE-2026-80112 HIGH Patched 7.8 2026-09-04 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability …
CVE-2026-9317 HIGH Patched 8.1 2026-09-04 Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by …
CVE-2026-85656 HIGH Patched 7.8 2026-09-04 An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root pri…
CVE-2026-85654 HIGH Patched 7.8 2026-09-04 Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependen…
CVE-2026-82538 HIGH 8.8 2026-09-04 ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is…
CVE-2026-61686 HIGH 7.5 2026-09-04 SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` afte…
CVE-2026-19534 HIGH Patched 7.5 2026-09-04 undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A defaul…
CVE-2021-44320 HIGH 7.5 2026-09-04 Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., video s…
CVE-2021-44319 HIGH 7.5 2026-09-04 Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication attack, allowing remote and unaut…
CVE-2026-85152 HIGH Patched 7.4 2026-09-04 undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Poo…
CVE-2026-84961 HIGH Patched 7.4 2026-09-04 undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot repres…
CVE-2026-18489 HIGH 7.4 2026-09-04 IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposur&hellip;
CVE-2026-18486 HIGH 8.8 2026-09-04 IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper&hellip;
CVE-2026-18221 HIGH 8.1 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
CVE-2026-18175 HIGH 8.1 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.
CVE-2026-77822 HIGH 8.2 2026-09-04 IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding.
CVE-2026-75169 HIGH 8.8 2026-09-04 An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with Admin role to up&hellip;
CVE-2026-75161 HIGH 8.8 2026-09-04 An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Stan&hellip;
CVE-2026-19306 HIGH 7.7 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JW&hellip;
CVE-2026-19305 HIGH 8.6 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.
CVE-2026-19304 HIGH 7.7 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy.
CVE-2026-19303 HIGH 8.1 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to&hellip;
CVE-2026-19300 HIGH 7.5 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.