Search
1,211 CVEs · High severity
CVEs (1,211, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 1,211 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-58353 | HIGH | Patched | 8.9 | 2026-07-23 | Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly accessible single booking view (e.g., /booking/<id>). … |
| CVE-2024-58355 | HIGH | Patched | 8.9 | 2026-07-23 | Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking view (e.g., https://app.cal.com/booking/<id>) rende… |
| CVE-2026-15212 | HIGH | 8.8 | 2026-07-23 | The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_req… | |
| CVE-2026-65917 | HIGH | Patched | 8.8 | 2026-07-23 | CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup hand… |
| CVE-2026-65690 | HIGH | Patched | 8.8 | 2026-07-23 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attac… |
| CVE-2026-65906 | HIGH | Patched | 8.8 | 2026-07-23 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible |
| CVE-2026-65897 | HIGH | Patched | 8.8 | 2026-07-23 | Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invite… |
| CVE-2026-65608 | HIGH | Patched | 8.8 | 2026-07-23 | Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() resolves blueprint data-*@: directives by calling c… |
| CVE-2026-59541 | HIGH | 8.8 | 2026-07-23 | Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions. | |
| CVE-2026-57785 | HIGH | 8.8 | 2026-07-23 | Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions. | |
| CVE-2026-16745 | HIGH | 8.8 | 2026-07-23 | A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can byp… | |
| CVE-2026-15017 | HIGH | 8.8 | 2026-07-23 | The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks… | |
| CVE-2026-60373 | HIGH | 8.8 | 2026-07-22 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a… | |
| CVE-2026-60439 | HIGH | 8.8 | 2026-07-22 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a… | |
| CVE-2026-60455 | HIGH | 8.8 | 2026-07-22 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a… | |
| CVE-2026-61246 | HIGH | 8.8 | 2026-07-22 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a… | |
| CVE-2026-60368 | HIGH | 8.8 | 2026-07-22 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a… | |
| CVE-2026-64832 | HIGH | 8.8 | 2026-07-22 | FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory… | |
| CVE-2026-64835 | HIGH | 8.8 | 2026-07-22 | FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger … | |
| CVE-2026-65013 | HIGH | Patched | 8.8 | 2026-07-22 | Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate othe… |
| CVE-2026-64830 | HIGH | 8.8 | 2026-07-22 | FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supp… | |
| CVE-2026-64831 | HIGH | 8.8 | 2026-07-22 | FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addres… | |
| CVE-2026-49499 | HIGH | 8.8 | 2026-07-22 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with re… | |
| CVE-2026-65603 | HIGH | Patched | 8.8 | 2026-07-22 | The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile self-update handler (processUserProfile(), the… |
| CVE-2026-14551 | HIGH | 8.8 | 2026-07-22 | The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-pr… |