Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

674 CVEs · High severity

CVEs (674, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 674 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-71220 HIGH 7.0 2026-09-03 A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds ch…
CVE-2026-71221 HIGH 7.0 2026-09-03 A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking…
CVE-2026-78409 HIGH 7.0 2026-09-02 The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag d…
CVE-2026-73725 HIGH Patched 7.0 2026-09-01 A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation of this vulnerability could allow a local attacker…
CVE-2026-84233 HIGH 7.0 2026-09-01 A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncomp…
CVE-2026-9331 HIGH 7.1 2026-09-08 The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing …
CVE-2026-81798 HIGH 7.1 2026-09-08 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appoi…
CVE-2026-84817 HIGH 7.1 2026-09-08 Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions.
CVE-2026-84818 HIGH 7.1 2026-09-08 Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions.
CVE-2026-84820 HIGH 7.1 2026-09-08 Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions.
CVE-2026-81781 HIGH 7.1 2026-09-08 Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects&hellip;
CVE-2026-80130 HIGH 7.1 2026-09-07 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. A low privi&hellip;
CVE-2026-81404 HIGH Patched 7.1 2026-09-05 The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attacke&hellip;
CVE-2026-86090 HIGH Patched 7.1 2026-09-04 ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST&hellip;
CVE-2026-86091 HIGH Patched 7.1 2026-09-04 ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bin&hellip;
CVE-2026-80117 HIGH Patched 7.1 2026-09-04 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in D&hellip;
CVE-2026-80118 HIGH Patched 7.1 2026-09-04 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclo&hellip;
CVE-2026-80113 HIGH Patched 7.1 2026-09-04 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in D&hellip;
CVE-2022-35499 HIGH 7.1 2026-09-04 In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.
CVE-2026-19051 HIGH Patched 7.1 2026-09-04 Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data. This issue affects Menulux Portal: before 20&hellip;
CVE-2026-16281 HIGH Patched 7.1 2026-09-04 The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or&hellip;
CVE-2026-85451 HIGH 7.1 2026-09-03 MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command a&hellip;
CVE-2026-53728 HIGH Patched 7.1 2026-09-03 Medplum is a developer platform that enables development of healthcare apps. Prior to version 5.1.6, the external identity provider callback at GET /auth/external accepts a&hellip;
CVE-2026-85395 HIGH Patched 7.1 2026-09-03 UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers wit&hellip;
CVE-2026-85390 HIGH 7.1 2026-09-03 Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform admin&hellip;