Search
4,825 CVEs · High severity
CVEs (4,825, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 4,825 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48019 | HIGH | Patched | 8.9 | 2026-09-04 | Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony… |
| CVE-2026-82653 | HIGH | 8.9 | 2026-08-30 | SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into… | |
| CVE-2026-82654 | HIGH | 8.9 | 2026-08-30 | SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to … | |
| CVE-2025-30156 | HIGH | Patched | 8.9 | 2026-08-28 | Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol enc… |
| CVE-2026-30864 | HIGH | Patched | 8.9 | 2026-08-24 | Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. Th… |
| CVE-2026-19200 | HIGH | 8.9 | 2026-08-24 | The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global ar… | |
| CVE-2026-77638 | HIGH | Patched | 8.9 | 2026-08-20 | Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the c… |
| CVE-2026-18193 | HIGH | 8.9 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses. | |
| CVE-2026-73570 | HIGH | Patched | 8.9 | 2026-08-13 | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enab… |
| CVE-2026-18099 | HIGH | 8.9 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to improper neutralization of user-controlled input. | |
| CVE-2026-57858 | HIGH | 8.9 | 2026-08-12 | Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owne… | |
| CVE-2026-62650 | HIGH | 8.8 | 2026-09-08 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforce… | |
| CVE-2026-86439 | HIGH | Patched | 8.8 | 2026-09-07 | knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project di… |
| CVE-2026-86482 | HIGH | Patched | 8.8 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation |
| CVE-2026-86427 | HIGH | Patched | 8.8 | 2026-09-07 | LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to inject arbitrary rrdtool arguments b… |
| CVE-2026-86404 | HIGH | 8.8 | 2026-09-07 | EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list… | |
| CVE-2026-19633 | HIGH | Patched | 8.8 | 2026-09-06 | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that c… |
| CVE-2026-18480 | HIGH | Patched | 8.8 | 2026-09-06 | The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing use… |
| CVE-2026-86166 | HIGH | 8.8 | 2026-09-06 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server… | |
| CVE-2025-9049 | HIGH | 8.8 | 2026-09-05 | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_… | |
| CVE-2026-86177 | HIGH | Patched | 8.8 | 2026-09-05 | Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute … |
| CVE-2026-86169 | HIGH | 8.8 | 2026-09-05 | Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the sec… | |
| CVE-2026-81543 | HIGH | 8.8 | 2026-09-05 | The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capab… | |
| CVE-2026-77826 | HIGH | Patched | 8.8 | 2026-09-05 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, all… |
| CVE-2026-19887 | HIGH | 8.8 | 2026-09-05 | The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the… |