Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

9,180 CVEs · High severity

CVEs (9,180, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 9,180 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2024-58353 HIGH Patched 8.9 2026-07-23 Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly accessible single booking view (e.g., /booking/<id>). &hellip;
CVE-2024-58355 HIGH Patched 8.9 2026-07-23 Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking view (e.g., https://app.cal.com/booking/<id>) rende&hellip;
CVE-2026-15416 HIGH 8.9 2026-07-14 A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-s&hellip;
CVE-2026-58424 HIGH 8.9 2026-07-03 Permanent Fork PR Workflow Approval Gate Bypass
CVE-2026-52798 HIGH Patched 8.9 2026-06-24 Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server side via /-/api/sanitize_ipynb, the inserted content i&hellip;
CVE-2026-43984 HIGH 8.9 2026-06-04 Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_errors` to any authenticated user, including guest us&hellip;
CVE-2026-42611 HIGH Patched 8.9 2026-05-11 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can cause XSS with the injection of svg element. The XSS&hellip;
CVE-2026-42556 HIGH Patched 8.9 2026-05-08 Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store arbitrary HTML in post co&hellip;
CVE-2026-5787 HIGH Patched 8.9 2026-05-07 An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry&hellip;
CVE-2026-38949 HIGH 8.9 2026-04-28 Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add/content?type=image endpoint. The application fails &hellip;
CVE-2026-15212 HIGH 8.8 2026-07-23 The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_req&hellip;
CVE-2026-65917 HIGH Patched 8.8 2026-07-23 CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup hand&hellip;
CVE-2026-65690 HIGH Patched 8.8 2026-07-23 Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attac&hellip;
CVE-2026-65906 HIGH Patched 8.8 2026-07-23 In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
CVE-2026-65897 HIGH Patched 8.8 2026-07-23 Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invite&hellip;
CVE-2026-65608 HIGH Patched 8.8 2026-07-23 Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() resolves blueprint data-*@: directives by calling c&hellip;
CVE-2026-59541 HIGH 8.8 2026-07-23 Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.
CVE-2026-57785 HIGH 8.8 2026-07-23 Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.
CVE-2026-16745 HIGH 8.8 2026-07-23 A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can byp&hellip;
CVE-2026-15017 HIGH 8.8 2026-07-23 The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks&hellip;
CVE-2026-60373 HIGH 8.8 2026-07-22 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a&hellip;
CVE-2026-60439 HIGH 8.8 2026-07-22 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a&hellip;
CVE-2026-60455 HIGH 8.8 2026-07-22 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a&hellip;
CVE-2026-61246 HIGH 8.8 2026-07-22 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a&hellip;
CVE-2026-60368 HIGH 8.8 2026-07-22 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a&hellip;