s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVEs

Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.

Reset

228874 CVEs matched. Showing 501–550 (page 11 of 4578).

HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.

Click a column header to sort all results; click the active column again to reverse.

CVE-ID ↕ Title ↕ Severity ↕ Score (overview) ↕ NVD Score MSRC Score CNA ↕ Published ↕ Remediations Threat Source
CVE-2026-80513 wpForo Forum < 3.1.6 - Subscriber+ PHP Object Injection via Profile Fields — — — — WPScan 2026-09-24 — — raw · ⬇
CVE-2026-80338 CMB2 < 2.13.0 - Subscriber+ Arbitrary Option Corruption via oEmbed Handler — — — — WPScan 2026-09-24 — — raw · ⬇
CVE-2026-74991 WPForms Lite 1.8.8.2 - 2.0.1.1 - Unauthenticated Stripe Refund and Subscription Cancellation via External PaymentIntent — — 6.8 — WPScan 2026-09-24 — — raw · ⬇
CVE-2026-97177 Keycloak-services: keycloak-services: generic user update bypasses denied reset-password permission MEDIUM 6.6 — — redhat 2026-09-24 — — raw · ⬇
CVE-2026-97176 Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cookie authenticator MEDIUM 4.2 4.2 — redhat 2026-09-24 — — raw · ⬇
CVE-2026-14780 PaperCut NG/MF: Remote Code Execution via Scripting Subsystem HIGH 7.5 — — PaperCut 2026-09-24 — ⚠ Threat raw · ⬇
CVE-2026-97155 CVE-2026-97155 MEDIUM 6.5 — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-96898 yhx070424 ShopXO Ueditor Upload ueditor.php path traversal MEDIUM 6.9 — — VulDB 2026-09-24 — — raw · ⬇
CVE-2026-97152 CVE-2026-97152 HIGH 8.6 — — mitre 2026-09-24 — ⚠ Threat raw · ⬇
CVE-2026-96892 Edimax BR-6428nC goform websRedirect redirect MEDIUM 5.3 4.3 — VulDB 2026-09-24 — — raw · ⬇
CVE-2026-97151 CVE-2026-97151 HIGH 8.4 — — mitre 2026-09-24 — ⚠ Threat raw · ⬇
CVE-2026-96891 D-Link DIR-825 rp-l2tp tunnel.c tunnel_set_params out-of-bounds write CRITICAL 9.3 9.8 — VulDB 2026-09-24 — ⚠ Threat raw · ⬇
CVE-2026-96884 MantisZip Preview MainWindow.UI.cs Path.Combine path traversal MEDIUM 5.3 6.3 — VulDB 2026-09-24 — — raw · ⬇
CVE-2026-96882 TaleLin lin-cms-spring-boot book Endpoint BookController.java searchBook improper authorization MEDIUM 6.9 5.3 — VulDB 2026-09-24 — — raw · ⬇
CVE-2026-97149 CVE-2026-97149 MEDIUM 5.3 — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-96881 TaleLin lin-cms-spring-boot book Endpoint BookController.java getBooks improper authorization MEDIUM 6.9 — — VulDB 2026-09-24 — — raw · ⬇
CVE-2026-96880 TaleLin lin-cms-spring-boot book Endpoint BookController.java getBook improper authorization MEDIUM 6.9 — — VulDB 2026-09-24 — — raw · ⬇
CVE-2026-97056 SigNoz before 0.143.0 Insufficient Session Expiration Authentication Bypass HIGH 7.6 — — VulnCheck 2026-09-24 — ⚠ Threat raw · ⬇
CVE-2026-97055 SigNoz before 0.143.0 Authentication Bypass via Empty JWT Secret CRITICAL 9.2 — — VulnCheck 2026-09-24 — ⚠ Threat raw · ⬇
CVE-2026-96810 huanzi-qch base-admin Add User CommonController.java save cross site scripting MEDIUM 5.1 — — VulDB 2026-09-24 — — raw · ⬇
CVE-2026-96803 java110 MicroCommunity fallBack API Endpoint BusinessApi.java QueryServiceSMOImpl.fallBack sql injection MEDIUM 6.9 7.3 — VulDB 2026-09-24 10 — raw · ⬇
CVE-2026-18467 Paytium: Mollie payment forms & donations <= 5.0.3 - Unauthenticated Privilege Escalation via 'pt_form_field[pt-user-rol… CRITICAL 9.8 9.8 — Wordfence 2026-09-24 1 ⚠ Threat raw · ⬇
CVE-2026-96777 Forma LMS Multi-User-Selector AJAX Endpoint getData getDataTask sql injection MEDIUM 5.3 6.3 — VulDB 2026-09-24 10 — raw · ⬇
CVE-2026-96774 SPON Communications IP Network Audio Device XC-9603 Configuration File Download sys_cfg.txt loadCfg information disclosu… MEDIUM 6.9 5.3 — VulDB 2026-09-24 10 — raw · ⬇
CVE-2026-96773 Intelliants Subrion CMS Login Page login.php authorize redirect MEDIUM 5.3 4.3 — VulDB 2026-09-24 10 — raw · ⬇
CVE-2026-96772 Intelliants Subrion CMS actions.json assign-owner information disclosure MEDIUM 6.9 5.3 — VulDB 2026-09-24 10 — raw · ⬇
CVE-2026-96764 kvcache-ai mooncake Regular Expression GetReplicaListByRegex allocation of resources MEDIUM 5.3 4.3 — VulDB 2026-09-24 10 — raw · ⬇
CVE-2026-96763 kvcache-ai mooncake MountSegment Request Processing segment.cpp access control MEDIUM 5.3 5.4 — VulDB 2026-09-24 10 — raw · ⬇
CVE-2026-88368 CVE-2026-88368 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88387 CVE-2026-88387 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88390 CVE-2026-88390 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88385 CVE-2026-88385 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88388 CVE-2026-88388 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88386 CVE-2026-88386 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88383 CVE-2026-88383 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88384 CVE-2026-88384 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88378 CVE-2026-88378 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88372 CVE-2026-88372 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88370 CVE-2026-88370 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88376 CVE-2026-88376 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88367 CVE-2026-88367 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88382 CVE-2026-88382 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88362 CVE-2026-88362 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88377 CVE-2026-88377 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88371 CVE-2026-88371 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88373 CVE-2026-88373 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88366 CVE-2026-88366 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88369 CVE-2026-88369 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88360 CVE-2026-88360 — — — — mitre 2026-09-24 — — raw · ⬇
CVE-2026-88365 CVE-2026-88365 — — — — mitre 2026-09-24 — — raw · ⬇