Search
11,548 CVEs · High severity
CVEs (11,548, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 11,548 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-9331 | HIGH | 7.1 | 2026-09-08 | The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing … | |
| CVE-2026-67367 | HIGH | 8.6 | 2026-09-08 | A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All ve… | |
| CVE-2026-62650 | HIGH | 8.8 | 2026-09-08 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforce… | |
| CVE-2026-62649 | HIGH | 7.5 | 2026-09-08 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The web server does not properly limit or manage system resources when processing a high volume… | |
| CVE-2026-62648 | HIGH | 7.5 | 2026-09-08 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL component contained in pre-authenticated HTTP messages is not properly va… | |
| CVE-2026-62647 | HIGH | 7.4 | 2026-09-08 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevant values (such as session identif… | |
| CVE-2026-62646 | HIGH | 7.4 | 2026-09-08 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier is generated using an algorithm with insufficient randomness, resulting in… | |
| CVE-2026-34223 | HIGH | 8.2 | 2026-09-08 | A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desig… | |
| CVE-2026-84820 | HIGH | 7.1 | 2026-09-08 | Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions. | |
| CVE-2026-84818 | HIGH | 7.1 | 2026-09-08 | Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions. | |
| CVE-2026-84817 | HIGH | 7.1 | 2026-09-08 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions. | |
| CVE-2026-81806 | HIGH | 7.2 | 2026-09-08 | Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09. | |
| CVE-2026-81798 | HIGH | 7.1 | 2026-09-08 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appoi… | |
| CVE-2026-81790 | HIGH | Patched | 7.5 | 2026-09-08 | Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels… |
| CVE-2026-81781 | HIGH | 7.1 | 2026-09-08 | Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects… | |
| CVE-2026-76561 | HIGH | 7.2 | 2026-09-08 | A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile … | |
| CVE-2026-71375 | HIGH | Patched | 7.4 | 2026-09-08 | Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 bef… |
| CVE-2026-48888 | HIGH | Patched | 7.5 | 2026-09-08 | Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0. |
| CVE-2026-76967 | HIGH | 7.8 | 2026-09-08 | SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges… | |
| CVE-2026-76958 | HIGH | 8.5 | 2026-09-08 | SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could sub… | |
| CVE-2026-66767 | HIGH | 7.7 | 2026-09-08 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buf… | |
| CVE-2026-86544 | HIGH | Patched | 8.1 | 2026-09-07 | knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with r… |
| CVE-2026-86541 | HIGH | Patched | 8.3 | 2026-09-07 | knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the proj… |
| CVE-2026-86540 | HIGH | Patched | 7.8 | 2026-09-07 | knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by c… |
| CVE-2026-86539 | HIGH | 7.2 | 2026-09-07 | knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied … |