Search
11,582 CVEs · High severity
CVEs (11,582, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 201–225 of 11,582 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-80114 | HIGH | Patched | 7.8 | 2026-09-04 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in… |
| CVE-2026-80113 | HIGH | Patched | 7.1 | 2026-09-04 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in D… |
| CVE-2026-80112 | HIGH | Patched | 7.8 | 2026-09-04 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability … |
| CVE-2026-9317 | HIGH | Patched | 8.1 | 2026-09-04 | Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by … |
| CVE-2026-85656 | HIGH | Patched | 7.8 | 2026-09-04 | An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root pri… |
| CVE-2026-85654 | HIGH | Patched | 7.8 | 2026-09-04 | Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependen… |
| CVE-2026-82538 | HIGH | 8.8 | 2026-09-04 | ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is… | |
| CVE-2026-61686 | HIGH | 7.5 | 2026-09-04 | SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` afte… | |
| CVE-2026-19534 | HIGH | Patched | 7.5 | 2026-09-04 | undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A defaul… |
| CVE-2021-44320 | HIGH | 7.5 | 2026-09-04 | Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., video s… | |
| CVE-2021-44319 | HIGH | 7.5 | 2026-09-04 | Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication attack, allowing remote and unaut… | |
| CVE-2026-85152 | HIGH | Patched | 7.4 | 2026-09-04 | undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Poo… |
| CVE-2026-84961 | HIGH | Patched | 7.4 | 2026-09-04 | undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot repres… |
| CVE-2026-18489 | HIGH | 7.4 | 2026-09-04 | IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposur… | |
| CVE-2026-18486 | HIGH | 8.8 | 2026-09-04 | IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper… | |
| CVE-2026-18221 | HIGH | 8.1 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters. | |
| CVE-2026-18175 | HIGH | 8.1 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher. | |
| CVE-2026-77822 | HIGH | 8.2 | 2026-09-04 | IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding. | |
| CVE-2026-75169 | HIGH | 8.8 | 2026-09-04 | An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with Admin role to up… | |
| CVE-2026-75161 | HIGH | 8.8 | 2026-09-04 | An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Stan… | |
| CVE-2026-19306 | HIGH | 7.7 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JW… | |
| CVE-2026-19305 | HIGH | 8.6 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery. | |
| CVE-2026-19304 | HIGH | 7.7 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy. | |
| CVE-2026-19303 | HIGH | 8.1 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to… | |
| CVE-2026-19300 | HIGH | 7.5 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields. |