Search
28,517 CVEs · High severity
CVEs (28,517, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 28,517 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48019 | HIGH | Patched | 8.9 | 2026-09-04 | Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony… |
| CVE-2026-82653 | HIGH | 8.9 | 2026-08-30 | SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into… | |
| CVE-2026-82654 | HIGH | 8.9 | 2026-08-30 | SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to … | |
| CVE-2025-30156 | HIGH | Patched | 8.9 | 2026-08-28 | Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol enc… |
| CVE-2026-30864 | HIGH | Patched | 8.9 | 2026-08-24 | Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. Th… |
| CVE-2026-19200 | HIGH | 8.9 | 2026-08-24 | The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global ar… | |
| CVE-2026-77638 | HIGH | Patched | 8.9 | 2026-08-20 | Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the c… |
| CVE-2026-18193 | HIGH | 8.9 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses. | |
| CVE-2026-73570 | HIGH | Patched | 8.9 | 2026-08-13 | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enab… |
| CVE-2026-18099 | HIGH | 8.9 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to improper neutralization of user-controlled input. | |
| CVE-2026-57858 | HIGH | 8.9 | 2026-08-12 | Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owne… | |
| CVE-2026-58154 | HIGH | Patched | 8.9 | 2026-07-29 | Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9,… |
| CVE-2026-16496 | HIGH | Patched | 8.9 | 2026-07-28 | The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains anot… |
| CVE-2024-58353 | HIGH | Patched | 8.9 | 2026-07-23 | Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly accessible single booking view (e.g., /booking/<id>). … |
| CVE-2024-58355 | HIGH | Patched | 8.9 | 2026-07-23 | Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking view (e.g., https://app.cal.com/booking/<id>) rende… |
| CVE-2026-15416 | HIGH | 8.9 | 2026-07-14 | A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-s… | |
| CVE-2026-58424 | HIGH | 8.9 | 2026-07-03 | Permanent Fork PR Workflow Approval Gate Bypass | |
| CVE-2026-52798 | HIGH | Patched | 8.9 | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server side via /-/api/sanitize_ipynb, the inserted content i… |
| CVE-2026-43984 | HIGH | 8.9 | 2026-06-04 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_errors` to any authenticated user, including guest us… | |
| CVE-2026-42611 | HIGH | Patched | 8.9 | 2026-05-11 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can cause XSS with the injection of svg element. The XSS… |
| CVE-2026-42556 | HIGH | Patched | 8.9 | 2026-05-08 | Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store arbitrary HTML in post co… |
| CVE-2026-5787 | HIGH | Patched | 8.9 | 2026-05-07 | An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry… |
| CVE-2026-38949 | HIGH | 8.9 | 2026-04-28 | Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add/content?type=image endpoint. The application fails … | |
| CVE-2026-5921 | HIGH | Patched | 8.9 | 2026-04-21 | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to extract sensitive environment variables from the i… |
| CVE-2026-40487 | HIGH | 8.9 | 2026-04-18 | Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other… |