Search
674 CVEs · High severity
CVEs (674, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 674 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-65643 | HIGH | Patched | 8.8 | 2026-09-01 | Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root. |
| CVE-2026-19573 | HIGH | 7.2 | 2026-09-01 | The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doCommentShortcode’ function in all versions up to, and including, … | |
| CVE-2026-19796 | HIGH | 7.2 | 2026-09-01 | The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter… | |
| CVE-2026-19806 | HIGH | 8.8 | 2026-09-01 | The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administ… | |
| CVE-2026-19952 | HIGH | 7.5 | 2026-09-01 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all … | |
| CVE-2026-75921 | HIGH | 7.2 | 2026-09-01 | The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to Arbitrar… | |
| CVE-2026-19914 | HIGH | 7.2 | 2026-09-01 | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_order' parameter in all versions up to, and including, 2.12.1 due t… | |
| CVE-2026-25706 | HIGH | 7.5 | 2026-09-01 | Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - … | |
| CVE-2026-59680 | HIGH | 8.0 | 2026-09-01 | An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb r… | |
| CVE-2026-59681 | HIGH | 8.8 | 2026-09-01 | A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory configuration values to execute arbitrary commands as root on the… | |
| CVE-2026-84059 | HIGH | 7.4 | 2026-09-01 | A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 20260704. The affected element is the function ArmAngstromInstructionSet of the file /CGI?RestApi=SetHostname. Ex… | |
| CVE-2026-76111 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke admi… | |
| CVE-2026-83595 | HIGH | 8.1 | 2026-09-01 | AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform state-changing actions by crafting GET requests that … | |
| CVE-2026-84187 | HIGH | 8.2 | 2026-09-01 | AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticated attackers to mark arbitrary scheduled broadcasts as failed … | |
| CVE-2026-84189 | HIGH | Patched | 8.1 | 2026-09-01 | LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the de… |
| CVE-2026-84190 | HIGH | Patched | 7.2 | 2026-09-01 | LibreNMS versions before 26.5.0 contain a remote code execution vulnerability in the AboutController where the snmpget configuration parameter is passed to shell_exec() wit… |
| CVE-2026-84192 | HIGH | Patched | 7.1 | 2026-09-01 | LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without escaping. An at… |
| CVE-2026-84195 | HIGH | Patched | 7.7 | 2026-09-01 | Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorizatio… |
| CVE-2026-84196 | HIGH | Patched | 7.7 | 2026-09-01 | Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecti… |
| CVE-2026-84199 | HIGH | Patched | 7.7 | 2026-09-01 | Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not valid… |
| CVE-2026-58575 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges t… | |
| CVE-2026-79683 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write a… | |
| CVE-2026-84117 | HIGH | Patched | 8.8 | 2026-09-01 | Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155. |
| CVE-2026-84123 | HIGH | Patched | 8.8 | 2026-09-01 | Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbi… |
| CVE-2026-84128 | HIGH | Patched | 8.8 | 2026-09-01 | Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155. |