Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

140,231 CVEs · High severity

EOL hidden · Show all products

CVEs (140,231, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 140,231 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9331 HIGH 7.1 2026-09-08 The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing …
CVE-2026-67367 HIGH 8.6 2026-09-08 A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All ve&hellip;
CVE-2026-62649 HIGH 7.5 2026-09-08 A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The web server does not properly limit or manage system resources when processing a high volume&hellip;
CVE-2026-62650 HIGH 8.8 2026-09-08 A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforce&hellip;
CVE-2026-62646 HIGH 7.4 2026-09-08 A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier is generated using an algorithm with insufficient randomness, resulting in&hellip;
CVE-2026-62647 HIGH 7.4 2026-09-08 A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevant values (such as session identif&hellip;
CVE-2026-62648 HIGH 7.5 2026-09-08 A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL component contained in pre-authenticated HTTP messages is not properly va&hellip;
CVE-2026-34223 HIGH 8.2 2026-09-08 A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desig&hellip;
CVE-2026-81798 HIGH 7.1 2026-09-08 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appoi&hellip;
CVE-2026-81806 HIGH 7.2 2026-09-08 Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09.
CVE-2026-84817 HIGH 7.1 2026-09-08 Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions.
CVE-2026-84818 HIGH 7.1 2026-09-08 Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions.
CVE-2026-84820 HIGH 7.1 2026-09-08 Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions.
CVE-2026-76561 HIGH 7.2 2026-09-08 A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile &hellip;
CVE-2026-81781 HIGH 7.1 2026-09-08 Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects&hellip;
CVE-2026-81790 HIGH Patched 7.5 2026-09-08 Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels&hellip;
CVE-2026-71375 HIGH Patched 7.4 2026-09-08 Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 bef&hellip;
CVE-2026-48888 HIGH Patched 7.5 2026-09-08 Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0.
CVE-2026-76967 HIGH 7.8 2026-09-08 SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges&hellip;
CVE-2026-76958 HIGH 8.5 2026-09-08 SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could sub&hellip;
CVE-2026-66767 HIGH 7.7 2026-09-08 SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buf&hellip;
CVE-2026-86544 HIGH Patched 8.1 2026-09-07 knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with r&hellip;
CVE-2026-86439 HIGH Patched 8.8 2026-09-07 knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project di&hellip;
CVE-2026-86538 HIGH Patched 7.5 2026-09-07 knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary fil&hellip;
CVE-2026-86539 HIGH 7.2 2026-09-07 knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied &hellip;