Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

1,211 CVEs · High severity

CVEs (1,211, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 1,211 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9833 HIGH Patched 7.1 2026-07-20 The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters before reflecting it in …
CVE-2026-9762 HIGH 7.8 2026-07-17 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.
CVE-2026-9713 HIGH 7.5 2026-07-23 The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed…
CVE-2026-9323 HIGH 8.1 2026-07-18 The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that …
CVE-2026-9171 HIGH 7.5 2026-07-17 IBM PowerVM Novalink are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the s…
CVE-2026-9147 HIGH 7.8 2026-07-18 uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (f…
CVE-2026-8933 HIGH 7.8 2026-07-21 A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution en…
CVE-2026-8396 HIGH Patched 7.5 2026-07-17 Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Data External Linking. This issue affects NetGIS: from…
CVE-2026-8082 HIGH Patched 7.5 2026-07-21 The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowin…
CVE-2026-8056 HIGH Patched 8.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the parameter f…
CVE-2026-7872 HIGH Patched 7.5 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user.
CVE-2026-7755 HIGH Patched 8.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files.
CVE-2026-7754 HIGH Patched 7.7 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the …
CVE-2026-7667 HIGH Patched 8.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted Co…
CVE-2026-7534 HIGH 7.2 2026-07-23 The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions …
CVE-2026-7488 HIGH 7.5 2026-07-17 Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This issue affects E-Commerce: …
CVE-2026-7232 HIGH 7.2 2026-07-23 The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due to ins…
CVE-2026-7189 HIGH 7.5 2026-07-17 Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs. T…
CVE-2026-6952 HIGH 7.2 2026-07-21 A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could a…
CVE-2026-6656 HIGH 7.5 2026-07-20 Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This allows discrepancies in tim…
CVE-2026-65919 HIGH Patched 7.5 2026-07-23 Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-suppli…
CVE-2026-65918 HIGH Patched 7.1 2026-07-23 PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes un…
CVE-2026-65917 HIGH Patched 8.8 2026-07-23 CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup hand…
CVE-2026-65916 HIGH Patched 8.1 2026-07-23 CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kil…
CVE-2026-65908 HIGH Patched 8.6 2026-07-23 In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open