Search
674 CVEs · High severity
CVEs (674, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 674 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-38489 | HIGH | 8.2 | 2026-09-03 | HDD password plaintext is stored in a UEFI variable. | |
| CVE-2021-44320 | HIGH | 7.5 | 2026-09-04 | Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., video s… | |
| CVE-2022-35499 | HIGH | 7.1 | 2026-09-04 | In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL. | |
| CVE-2022-51009 | HIGH | Patched | 7.5 | 2026-09-06 | PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin pack… |
| CVE-2022-51017 | HIGH | Patched | 7.5 | 2026-09-07 | PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 byte TAG_S… |
| CVE-2023-20576 | HIGH | 7.7 | 2026-09-02 | Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation. | |
| CVE-2023-20577 | HIGH | 7.4 | 2026-09-02 | A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution. | |
| CVE-2024-14047 | HIGH | 7.2 | 2026-09-01 | A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with ex… | |
| CVE-2024-35585 | HIGH | Patched | 8.6 | 2026-09-02 | Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication. |
| CVE-2025-12737 | HIGH | 8.4 | 2026-09-03 | The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative… | |
| CVE-2025-15485 | HIGH | 8.2 | 2026-09-02 | The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the … | |
| CVE-2025-46418 | HIGH | 7.6 | 2026-09-02 | Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition. | |
| CVE-2025-9049 | HIGH | 8.8 | 2026-09-05 | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_… | |
| CVE-2026-0799 | HIGH | 8.7 | 2026-09-05 | In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF inter… | |
| CVE-2026-10195 | HIGH | 8.8 | 2026-09-01 | The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 8.0.1. This is due to insufficient input sanitization of the FFmpe… | |
| CVE-2026-12483 | HIGH | 7.5 | 2026-09-04 | The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up to and including 5.1.5. This is due to insufficient input validation in… | |
| CVE-2026-12526 | HIGH | Patched | 8.1 | 2026-09-02 | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user a… |
| CVE-2026-12865 | HIGH | Patched | 7.1 | 2026-09-02 | The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before reflecting them into input-attribute values on its admin pages (one… |
| CVE-2026-14199 | HIGH | 7.1 | 2026-09-02 | Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concaten… | |
| CVE-2026-14296 | HIGH | 7.5 | 2026-09-07 | When using the Direct XIP update strategy, the main application image starts other cores (i.e. radio core), based on the currently active slot without additional verificati… | |
| CVE-2026-14357 | HIGH | 8.8 | 2026-09-02 | The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing no… | |
| CVE-2026-14444 | HIGH | 7.5 | 2026-09-07 | The WP Fusion (Pro) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.47.13. This is due to insufficient authorization chec… | |
| CVE-2026-14828 | HIGH | Patched | 8.8 | 2026-09-02 | Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticat… |
| CVE-2026-14957 | HIGH | 7.5 | 2026-09-02 | In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL w… | |
| CVE-2026-14982 | HIGH | 8.1 | 2026-09-02 | The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This mak… |