Search
1,211 CVEs · High severity
CVEs (1,211, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 1,211 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9833 | HIGH | Patched | 7.1 | 2026-07-20 | The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters before reflecting it in … |
| CVE-2026-9762 | HIGH | 7.8 | 2026-07-17 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control. | |
| CVE-2026-9713 | HIGH | 7.5 | 2026-07-23 | The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed… | |
| CVE-2026-9323 | HIGH | 8.1 | 2026-07-18 | The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that … | |
| CVE-2026-9171 | HIGH | 7.5 | 2026-07-17 | IBM PowerVM Novalink are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the s… | |
| CVE-2026-9147 | HIGH | 7.8 | 2026-07-18 | uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (f… | |
| CVE-2026-8933 | HIGH | 7.8 | 2026-07-21 | A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution en… | |
| CVE-2026-8396 | HIGH | Patched | 7.5 | 2026-07-17 | Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Data External Linking. This issue affects NetGIS: from… |
| CVE-2026-8082 | HIGH | Patched | 7.5 | 2026-07-21 | The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowin… |
| CVE-2026-8056 | HIGH | Patched | 8.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the parameter f… |
| CVE-2026-7872 | HIGH | Patched | 7.5 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user. |
| CVE-2026-7755 | HIGH | Patched | 8.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files. |
| CVE-2026-7754 | HIGH | Patched | 7.7 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the … |
| CVE-2026-7667 | HIGH | Patched | 8.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted Co… |
| CVE-2026-7534 | HIGH | 7.2 | 2026-07-23 | The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions … | |
| CVE-2026-7488 | HIGH | 7.5 | 2026-07-17 | Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This issue affects E-Commerce: … | |
| CVE-2026-7232 | HIGH | 7.2 | 2026-07-23 | The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due to ins… | |
| CVE-2026-7189 | HIGH | 7.5 | 2026-07-17 | Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs. T… | |
| CVE-2026-6952 | HIGH | 7.2 | 2026-07-21 | A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could a… | |
| CVE-2026-6656 | HIGH | 7.5 | 2026-07-20 | Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This allows discrepancies in tim… | |
| CVE-2026-65919 | HIGH | Patched | 7.5 | 2026-07-23 | Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-suppli… |
| CVE-2026-65918 | HIGH | Patched | 7.1 | 2026-07-23 | PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes un… |
| CVE-2026-65917 | HIGH | Patched | 8.8 | 2026-07-23 | CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup hand… |
| CVE-2026-65916 | HIGH | Patched | 8.1 | 2026-07-23 | CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kil… |
| CVE-2026-65908 | HIGH | Patched | 8.6 | 2026-07-23 | In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open |