Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

11,548 CVEs · High severity

CVEs (11,548, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 11,548 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-48019 HIGH Patched 8.9 2026-09-04 Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony…
CVE-2026-82653 HIGH 8.9 2026-08-30 SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into…
CVE-2026-82654 HIGH 8.9 2026-08-30 SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to …
CVE-2025-30156 HIGH Patched 8.9 2026-08-28 Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol enc…
CVE-2026-30864 HIGH Patched 8.9 2026-08-24 Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. Th…
CVE-2026-19200 HIGH 8.9 2026-08-24 The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global ar…
CVE-2026-77638 HIGH Patched 8.9 2026-08-20 Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the c…
CVE-2026-18193 HIGH 8.9 2026-08-13 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.
CVE-2026-73570 HIGH Patched 8.9 2026-08-13 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enab…
CVE-2026-18099 HIGH 8.9 2026-08-12 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to improper neutralization of user-controlled input.
CVE-2026-57858 HIGH 8.9 2026-08-12 Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owne…
CVE-2026-58154 HIGH Patched 8.9 2026-07-29 Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9,…
CVE-2026-16496 HIGH Patched 8.9 2026-07-28 The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains anot…
CVE-2024-58353 HIGH Patched 8.9 2026-07-23 Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly accessible single booking view (e.g., /booking/<id>). &hellip;
CVE-2024-58355 HIGH Patched 8.9 2026-07-23 Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking view (e.g., https://app.cal.com/booking/<id>) rende&hellip;
CVE-2026-15416 HIGH 8.9 2026-07-14 A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-s&hellip;
CVE-2026-58424 HIGH 8.9 2026-07-03 Permanent Fork PR Workflow Approval Gate Bypass
CVE-2026-52798 HIGH Patched 8.9 2026-06-24 Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server side via /-/api/sanitize_ipynb, the inserted content i&hellip;
CVE-2026-62650 HIGH 8.8 2026-09-08 A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforce&hellip;
CVE-2026-86439 HIGH Patched 8.8 2026-09-07 knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project di&hellip;
CVE-2026-86482 HIGH Patched 8.8 2026-09-07 In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation
CVE-2026-86427 HIGH Patched 8.8 2026-09-07 LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to inject arbitrary rrdtool arguments b&hellip;
CVE-2026-86404 HIGH 8.8 2026-09-07 EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list&hellip;
CVE-2026-19633 HIGH Patched 8.8 2026-09-06 PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that c&hellip;
CVE-2026-18480 HIGH Patched 8.8 2026-09-06 The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing use&hellip;