s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVEs

Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.

Reset

204905 CVEs matched. Showing 51–100 (page 2 of 4099).

HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.

Click a column header to sort all results; click the active column again to reverse.

CVE-ID Title Severity Score (overview) NVD Score MSRC Score CNA Published Remediations Threat Source
CVE-2026-47682 CVAT: Missing path-containment validation in multiple entry points allows arbitrary path writes HIGH 7.1 GitHub_M 2026-08-04 ⚠ Threat raw ·
CVE-2026-18810 H3C NX15 networkSetup missing authentication MEDIUM 6.9 VulDB 2026-08-04 raw ·
CVE-2026-70485 Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs HIGH 7.1 GitHub_M 2026-08-04 ⚠ Threat raw ·
CVE-2026-70484 Open WebUI: Users denied the image-generation permission can still generate images via chat completions MEDIUM 4.3 GitHub_M 2026-08-04 raw ·
CVE-2026-70483 Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint LOW 3.1 GitHub_M 2026-08-04 raw ·
CVE-2026-70482 Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client HIGH 8.1 GitHub_M 2026-08-04 ⚠ Threat raw ·
CVE-2026-16793 Remote Command Injection via OS Profile Password in Lenovo XClarity Orchestrator HIGH 8.7 lenovo 2026-08-04 ⚠ Threat raw ·
CVE-2026-16792 Global TLS Certificate Validation Bypass in Lenovo XClarity Orchestrator HIGH 7.0 lenovo 2026-08-04 ⚠ Threat raw ·
CVE-2026-16791 Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essentials OneCLI LOW 1.0 lenovo 2026-08-04 raw ·
CVE-2026-48154 GoRest: InMemorySecret2FA race condition allows process crash via concurrent map access MEDIUM 5.9 GitHub_M 2026-08-04 raw ·
CVE-2026-70481 Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages MEDIUM 5.4 GitHub_M 2026-08-04 raw ·
CVE-2026-70480 Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering MEDIUM 4.1 GitHub_M 2026-08-04 raw ·
CVE-2026-70479 Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader HIGH 7.7 GitHub_M 2026-08-04 ⚠ Threat raw ·
CVE-2026-18657 Executable Resolution from Untrusted Project Directory in Kiro CLI on Windows HIGH 8.5 AMZN 2026-08-04 ⚠ Threat raw ·
CVE-2026-70553 MaxSite CMS Unauthenticated RCE via Install Endpoint CRITICAL 9.3 VulnCheck 2026-08-04 ⚠ Threat raw ·
CVE-2026-70478 Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected ser… CRITICAL 9.2 GitHub_M 2026-08-04 ⚠ Threat raw ·
CVE-2026-18656 Executable Resolution from Untrusted Project Directory in Kiro IDE on Windows HIGH 8.5 AMZN 2026-08-04 ⚠ Threat raw ·
CVE-2026-70477 Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability CRITICAL 9.5 GitHub_M 2026-08-04 ⚠ Threat raw ·
CVE-2026-70552 MaxSite CMS 109.5 Unauthenticated AJAX Dispatcher Bypass via ajax.php CRITICAL 9.3 VulnCheck 2026-08-04 ⚠ Threat raw ·
CVE-2026-70476 Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation HIGH 8.3 GitHub_M 2026-08-04 ⚠ Threat raw ·
CVE-2026-70475 Flowise: Missing Authorization on Execution Update Endpoint HIGH 7.1 GitHub_M 2026-08-04 ⚠ Threat raw ·
CVE-2026-49435 Keysight IxChariot-related products stack-based buffer overflow CRITICAL 9.3 cisa-cg 2026-08-04 ⚠ Threat raw ·
CVE-2026-66300 SNOMED International Snowstorm reflected XSS LOW 2.3 cisa-cg 2026-08-04 raw ·
CVE-2026-69704 Atals-Livre SQL Injection via Unsanitized GET Parameter in supp() HIGH 7.0 VulnCheck 2026-08-04 ⚠ Threat raw ·
CVE-2026-47781 pdm: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing HIGH 8.4 GitHub_M 2026-08-04 ⚠ Threat raw ·
CVE-2026-69703 Atlas-Livre Unauthenticated Access via Admin Controllers Missing Exit CRITICAL 9.3 VulnCheck 2026-08-04 ⚠ Threat raw ·
CVE-2026-68743 Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v1 MEDIUM 5.5 redhat 2026-08-04 raw ·
CVE-2026-0163 CVE-2026-0163 Google_Devices 2026-08-04 raw ·
CVE-2026-13229 Zammad 7.0.1 - Improper authorization in ticket article attachment cloning HIGH 7.1 Fluid Attacks 2026-08-04 ⚠ Threat raw ·
CVE-2026-70474 Flowise: Cross-Workspace OAuth2 Credential Metadata Leak HIGH 7.6 GitHub_M 2026-08-04 ⚠ Threat raw ·
CVE-2026-47764 pdm: Path traversal in wheel installation via overridden write_to_fs HIGH 8.4 GitHub_M 2026-08-04 ⚠ Threat raw ·
CVE-2026-70473 Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history HIGH 8.3 GitHub_M 2026-08-04 ⚠ Threat raw ·
CVE-2026-70472 Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store HIGH 7.1 GitHub_M 2026-08-04 ⚠ Threat raw ·
CVE-2026-69702 SnailJob 1.7.0 Denial of Service via FuryUtil.deserialize OOM HIGH 7.1 VulnCheck 2026-08-04 ⚠ Threat raw ·
CVE-2026-70471 Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure HIGH 7.1 GitHub_M 2026-08-04 ⚠ Threat raw ·
CVE-2026-18830 Insufficient input validation in Amazon Bedrock AgentCore harness InvokeHarness API HIGH 8.6 AMZN 2026-08-04 ⚠ Threat raw ·
CVE-2026-47623 CVE-2026-47623 HIGH 8.2 nvidia 2026-08-04 ⚠ Threat raw ·
CVE-2026-47622 CVE-2026-47622 MEDIUM 5.3 nvidia 2026-08-04 raw ·
CVE-2026-47621 CVE-2026-47621 MEDIUM 6.5 nvidia 2026-08-04 raw ·
CVE-2026-47620 CVE-2026-47620 MEDIUM 6.5 nvidia 2026-08-04 raw ·
CVE-2026-47619 CVE-2026-47619 MEDIUM 6.6 nvidia 2026-08-04 raw ·
CVE-2026-47618 CVE-2026-47618 HIGH 7.5 nvidia 2026-08-04 ⚠ Threat raw ·
CVE-2026-47617 CVE-2026-47617 HIGH 7.5 nvidia 2026-08-04 ⚠ Threat raw ·
CVE-2026-70470 Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE CRITICAL 9.5 GitHub_M 2026-08-04 ⚠ Threat raw ·
CVE-2026-47616 CVE-2026-47616 HIGH 7.5 nvidia 2026-08-04 ⚠ Threat raw ·
CVE-2026-47615 CVE-2026-47615 HIGH 7.5 nvidia 2026-08-04 ⚠ Threat raw ·
CVE-2026-18790 Systerel S2OPC DeleteMonitoredItemsRequest state_machine.c out-of-bounds MEDIUM 4.8 VulDB 2026-08-04 raw ·
CVE-2026-47763 pdm: Project-Local State and Config Writes Follow Symlinks MEDIUM 6.8 GitHub_M 2026-08-04 raw ·
CVE-2026-47614 CVE-2026-47614 HIGH 7.5 nvidia 2026-08-04 ⚠ Threat raw ·
CVE-2026-47613 CVE-2026-47613 HIGH 7.5 nvidia 2026-08-04 ⚠ Threat raw ·