Search
1,211 CVEs · High severity
CVEs (1,211, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 1,211 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16584 | HIGH | Patched | 7.0 | 2026-07-23 | Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execu… |
| CVE-2026-61120 | HIGH | 7.0 | 2026-07-21 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficu… | |
| CVE-2026-61061 | HIGH | 7.0 | 2026-07-21 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2… | |
| CVE-2026-60833 | HIGH | 7.0 | 2026-07-21 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11.4. Difficult to exploit vulnerability all… | |
| CVE-2026-60705 | HIGH | 7.0 | 2026-07-21 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Diff… | |
| CVE-2026-60494 | HIGH | 7.0 | 2026-07-21 | Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation). The supported version that is affected is 9.2. Diffi… | |
| CVE-2026-46999 | HIGH | 7.0 | 2026-07-21 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework). Supported versions that are affected ar… | |
| CVE-2026-15968 | HIGH | Patched | 7.1 | 2026-07-23 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before … |
| CVE-2026-65918 | HIGH | Patched | 7.1 | 2026-07-23 | PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes un… |
| CVE-2026-65896 | HIGH | Patched | 7.1 | 2026-07-23 | Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint. PagesController… |
| CVE-2026-65540 | HIGH | 7.1 | 2026-07-23 | Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions. | |
| CVE-2026-65539 | HIGH | 7.1 | 2026-07-23 | Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions. | |
| CVE-2026-65510 | HIGH | 7.1 | 2026-07-23 | Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. | |
| CVE-2026-65511 | HIGH | 7.1 | 2026-07-23 | Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. | |
| CVE-2026-65492 | HIGH | 7.1 | 2026-07-23 | Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions. | |
| CVE-2026-65494 | HIGH | 7.1 | 2026-07-23 | Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions. | |
| CVE-2026-65488 | HIGH | 7.1 | 2026-07-23 | Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions. | |
| CVE-2026-61944 | HIGH | 7.1 | 2026-07-23 | Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions. | |
| CVE-2026-61947 | HIGH | 7.1 | 2026-07-23 | Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions. | |
| CVE-2026-59517 | HIGH | 7.1 | 2026-07-23 | Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions. | |
| CVE-2026-59512 | HIGH | 7.1 | 2026-07-23 | Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions. | |
| CVE-2026-57735 | HIGH | 7.1 | 2026-07-23 | Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions. | |
| CVE-2026-57767 | HIGH | 7.1 | 2026-07-23 | Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions. | |
| CVE-2026-57769 | HIGH | 7.1 | 2026-07-23 | Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions. | |
| CVE-2026-57809 | HIGH | 7.1 | 2026-07-23 | Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions. |