Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

674 CVEs · High severity

CVEs (674, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 674 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-48019 HIGH Patched 8.9 2026-09-04 Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony…
CVE-2026-62650 HIGH 8.8 2026-09-08 A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforce&hellip;
CVE-2026-86439 HIGH Patched 8.8 2026-09-07 knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project di&hellip;
CVE-2026-86482 HIGH Patched 8.8 2026-09-07 In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation
CVE-2026-86427 HIGH Patched 8.8 2026-09-07 LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to inject arbitrary rrdtool arguments b&hellip;
CVE-2026-86404 HIGH 8.8 2026-09-07 EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list&hellip;
CVE-2026-19633 HIGH Patched 8.8 2026-09-06 PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that c&hellip;
CVE-2026-18480 HIGH Patched 8.8 2026-09-06 The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing use&hellip;
CVE-2026-86166 HIGH 8.8 2026-09-06 A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server&hellip;
CVE-2025-9049 HIGH 8.8 2026-09-05 The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_&hellip;
CVE-2026-86177 HIGH Patched 8.8 2026-09-05 Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute &hellip;
CVE-2026-86169 HIGH 8.8 2026-09-05 Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the sec&hellip;
CVE-2026-81543 HIGH 8.8 2026-09-05 The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capab&hellip;
CVE-2026-77826 HIGH Patched 8.8 2026-09-05 The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, all&hellip;
CVE-2026-19887 HIGH 8.8 2026-09-05 The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the&hellip;
CVE-2026-52775 HIGH Patched 8.8 2026-09-05 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::de&hellip;
CVE-2026-77393 HIGH 8.8 2026-09-04 In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute g&hellip;
CVE-2026-82712 HIGH 8.8 2026-09-04 Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changi&hellip;
CVE-2026-82538 HIGH 8.8 2026-09-04 ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is&hellip;
CVE-2026-18486 HIGH 8.8 2026-09-04 IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper&hellip;
CVE-2026-19298 HIGH 8.8 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.
CVE-2026-85623 HIGH 8.8 2026-09-04 goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection. Attackers can distribute malicious recipes that execute &hellip;
CVE-2026-85607 HIGH 8.8 2026-09-04 Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/r&hellip;
CVE-2026-18198 HIGH 8.8 2026-09-04 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN O&hellip;
CVE-2026-85617 HIGH Patched 8.8 2026-09-04 snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside thei&hellip;