Search
674 CVEs · High severity
CVEs (674, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 674 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71220 | HIGH | 7.0 | 2026-09-03 | A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds ch… | |
| CVE-2026-71221 | HIGH | 7.0 | 2026-09-03 | A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking… | |
| CVE-2026-78409 | HIGH | 7.0 | 2026-09-02 | The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag d… | |
| CVE-2026-73725 | HIGH | Patched | 7.0 | 2026-09-01 | A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation of this vulnerability could allow a local attacker… |
| CVE-2026-84233 | HIGH | 7.0 | 2026-09-01 | A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncomp… | |
| CVE-2026-9331 | HIGH | 7.1 | 2026-09-08 | The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing … | |
| CVE-2026-81798 | HIGH | 7.1 | 2026-09-08 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appoi… | |
| CVE-2026-84817 | HIGH | 7.1 | 2026-09-08 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions. | |
| CVE-2026-84818 | HIGH | 7.1 | 2026-09-08 | Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions. | |
| CVE-2026-84820 | HIGH | 7.1 | 2026-09-08 | Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions. | |
| CVE-2026-81781 | HIGH | 7.1 | 2026-09-08 | Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects… | |
| CVE-2026-80130 | HIGH | 7.1 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. A low privi… | |
| CVE-2026-81404 | HIGH | Patched | 7.1 | 2026-09-05 | The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attacke… |
| CVE-2026-86090 | HIGH | Patched | 7.1 | 2026-09-04 | ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST… |
| CVE-2026-86091 | HIGH | Patched | 7.1 | 2026-09-04 | ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bin… |
| CVE-2026-80117 | HIGH | Patched | 7.1 | 2026-09-04 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in D… |
| CVE-2026-80118 | HIGH | Patched | 7.1 | 2026-09-04 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclo… |
| CVE-2026-80113 | HIGH | Patched | 7.1 | 2026-09-04 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in D… |
| CVE-2022-35499 | HIGH | 7.1 | 2026-09-04 | In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL. | |
| CVE-2026-19051 | HIGH | Patched | 7.1 | 2026-09-04 | Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data. This issue affects Menulux Portal: before 20… |
| CVE-2026-16281 | HIGH | Patched | 7.1 | 2026-09-04 | The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or… |
| CVE-2026-85451 | HIGH | 7.1 | 2026-09-03 | MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command a… | |
| CVE-2026-53728 | HIGH | Patched | 7.1 | 2026-09-03 | Medplum is a developer platform that enables development of healthcare apps. Prior to version 5.1.6, the external identity provider callback at GET /auth/external accepts a… |
| CVE-2026-85395 | HIGH | Patched | 7.1 | 2026-09-03 | UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers wit… |
| CVE-2026-85390 | HIGH | 7.1 | 2026-09-03 | Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform admin… |