Search
4,825 CVEs · High severity
CVEs (4,825, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 4,825 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-17510 | HIGH | Patched | 7.5 | 2026-08-09 | Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print_attribute() sizes the… |
| CVE-2026-10595 | HIGH | Patched | 7.5 | 2026-08-09 | A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability ar… |
| CVE-2026-16988 | HIGH | Patched | 7.5 | 2026-08-09 | The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthent… |
| CVE-2026-17017 | HIGH | Patched | 8.1 | 2026-08-09 | The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does no… |
| CVE-2026-17044 | HIGH | Patched | 8.6 | 2026-08-09 | The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection expl… |
| CVE-2026-18032 | HIGH | Patched | 7.5 | 2026-08-09 | The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the nonce guarding that act… |
| CVE-2026-18357 | HIGH | Patched | 7.5 | 2026-08-09 | The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allowing unauthenticated at… |
| CVE-2026-18464 | HIGH | Patched | 7.5 | 2026-08-09 | The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not… |
| CVE-2026-19341 | HIGH | 8.8 | 2026-08-09 | A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulati… | |
| CVE-2026-19342 | HIGH | 7.3 | 2026-08-09 | A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipu… | |
| CVE-2026-19343 | HIGH | 7.3 | 2026-08-09 | A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/AdminLogin.php. Executing a… | |
| CVE-2026-19344 | HIGH | 7.3 | 2026-08-09 | A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/comment_count_user.php. T… | |
| CVE-2026-19346 | HIGH | 8.8 | 2026-08-09 | A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the ar… | |
| CVE-2026-19351 | HIGH | 7.3 | 2026-08-09 | A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the l… | |
| CVE-2026-19355 | HIGH | 7.3 | 2026-08-09 | A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component m… | |
| CVE-2026-19374 | HIGH | 7.3 | 2026-08-09 | A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy… | |
| CVE-2026-19376 | HIGH | 7.3 | 2026-08-10 | A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File … | |
| CVE-2026-19379 | HIGH | 7.3 | 2026-08-10 | A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the … | |
| CVE-2026-19381 | HIGH | 7.8 | 2026-08-10 | A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the … | |
| CVE-2026-19384 | HIGH | 7.3 | 2026-08-10 | A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_a… | |
| CVE-2026-19387 | HIGH | 7.6 | 2026-08-10 | A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-b… | |
| CVE-2026-19389 | HIGH | 7.1 | 2026-08-10 | Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WM… | |
| CVE-2026-13170 | HIGH | Patched | 7.2 | 2026-08-10 | The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level acc… |
| CVE-2026-13600 | HIGH | Patched | 8.1 | 2026-08-10 | The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie du… |
| CVE-2026-14206 | HIGH | Patched | 7.5 | 2026-08-10 | The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users … |