Search
4,856 CVEs · High severity
CVEs (4,856, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 4,856 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86665 | HIGH | 7.3 | 2026-09-08 | A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::index of the file controllers/update.php. The manipulation lea… | |
| CVE-2026-83527 | HIGH | 8.1 | 2026-09-08 | An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access. | |
| CVE-2026-61517 | HIGH | 7.2 | 2026-09-08 | Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an OS command injection vulnerability in the ping diagnostic handler that allows authenticated administrators to exe… | |
| CVE-2026-18851 | HIGH | 8.8 | 2026-09-08 | Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges… | |
| CVE-2026-12648 | HIGH | Patched | 8.8 | 2026-09-08 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. |
| CVE-2026-12651 | HIGH | Patched | 8.8 | 2026-09-08 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. |
| CVE-2026-79377 | HIGH | 7.5 | 2026-09-08 | A heap overflow in the a2dp_decoder_sbc.cpp component of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Ser… | |
| CVE-2026-74239 | HIGH | Patched | 7.2 | 2026-09-08 | XenForo before 2.3.13 contains a path traversal vulnerability in the style archive importer on Windows deployments that allows authenticated non-super administrators with s… |
| CVE-2026-73311 | HIGH | Patched | 7.4 | 2026-09-08 | XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used aut… |
| CVE-2026-73312 | HIGH | Patched | 7.4 | 2026-09-08 | XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens a… |
| CVE-2026-73314 | HIGH | Patched | 7.5 | 2026-09-08 | XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated attackers to bypass payment signature val… |
| CVE-2026-73315 | HIGH | Patched | 8.6 | 2026-09-08 | XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to m… |
| CVE-2026-73316 | HIGH | Patched | 7.5 | 2026-09-08 | XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times b… |
| CVE-2026-73309 | HIGH | Patched | 7.4 | 2026-09-08 | XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by subm… |
| CVE-2026-33388 | HIGH | 7.4 | 2026-09-08 | An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with … | |
| CVE-2026-33389 | HIGH | 7.5 | 2026-09-08 | An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices witho… | |
| CVE-2026-75021 | HIGH | Patched | 8.1 | 2026-09-08 | fastify-cli starts the Node.js Inspector when a debug flag is used, but it ignores the explicit bind address the user supplies and binds the Inspector to a broadly reachabl… |
| CVE-2026-86713 | HIGH | 7.1 | 2026-09-08 | PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module's stop path where exit_and_cleanup() deletes the LoadMon object and frees the pe… | |
| CVE-2026-77968 | HIGH | 8.2 | 2026-09-08 | A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controll… | |
| CVE-2026-80219 | HIGH | 8.7 | 2026-09-08 | A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient with automatic grant approval (GrantMethod: au… | |
| CVE-2026-86711 | HIGH | Patched | 7.4 | 2026-09-08 | electerm before 5.3.15 exposes 40+ main-process functions through an unvalidated Electron IPC handler with no function-name allowlist or sender validation. Renderer-side sc… |
| CVE-2026-86712 | HIGH | Patched | 8.8 | 2026-09-08 | SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled de… |
| CVE-2026-74860 | HIGH | 8.5 | 2026-09-08 | A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Docu… | |
| CVE-2026-3174 | HIGH | 7.5 | 2026-09-08 | The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endp… | |
| CVE-2026-16502 | HIGH | 8.8 | 2026-09-08 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 via deserializati… |