s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVEs

Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.

Reset

228318 CVEs matched. Showing 51–100 (page 2 of 4567).

HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.

Click a column header to sort all results; click the active column again to reverse.

CVE-ID Title Severity Score (overview) NVD Score MSRC Score CNA Published Remediations Threat Source
CVE-2026-66074 RabbitMQ: ReDoS via management API ?name= filter MEDIUM 6.0 GitHub_M 2026-09-23 raw ·
CVE-2026-82369 Insufficient input sanitization of shell metacharacters in Brocade SANnav before 3.0.1a HIGH 8.6 brocade 2026-09-23 ⚠ Threat raw ·
CVE-2026-6718 Multiple Vulnerabilities in IBM Concert Software MEDIUM 6.2 6.2 ibm 2026-09-23 raw ·
CVE-2026-67232 RabbitMQ: Web-MQTT decompression bomb HIGH 8.2 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-67405 RabbitMQ: CSWSH on Web-STOMP / Web-MQTT (no Origin validation) MEDIUM 5.3 GitHub_M 2026-09-23 raw ·
CVE-2026-66075 RabbitMQ: Monitoring-tag user can restart federation links LOW 2.3 GitHub_M 2026-09-23 raw ·
CVE-2026-67219 RabbitMQ: Consistent-hash exchange unbounded weight MEDIUM 6.0 GitHub_M 2026-09-23 raw ·
CVE-2026-67228 RabbitMQ: Atom exhaustion: to_atom on runtime-parameter component MEDIUM 6.9 GitHub_M 2026-09-23 raw ·
CVE-2026-67235 RabbitMQ: AMQP 0-9-1 body assembly never validates accumulated size HIGH 7.1 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-66068 RabbitMQ: Shovel DEBUG log of full state exposes decrypted URIs MEDIUM 5.6 GitHub_M 2026-09-23 raw ·
CVE-2026-67229 RabbitMQ: Admin-only atom exhaustion: atomize_keys on vhost metadata MEDIUM 6.9 GitHub_M 2026-09-23 raw ·
CVE-2026-66080 RabbitMQ: Super-stream partitions unbounded allocation MEDIUM 5.9 GitHub_M 2026-09-23 raw ·
CVE-2026-67240 RabbitMQ: ReDoS via AMQP 1.0 SQL filter LIKE wildcard LOW 2.3 GitHub_M 2026-09-23 raw ·
CVE-2026-96556 Neethuharii CafeManagement AddCashierCode.php addcashier improper authorization MEDIUM 6.9 7.3 VulDB 2026-09-23 raw ·
CVE-2026-66072 RabbitMQ: Atom table exhaustion via stream `chunk_selector` MEDIUM 6.0 GitHub_M 2026-09-23 raw ·
CVE-2026-66067 RabbitMQ: Stream protocol skips per vhost per user connection limits MEDIUM 6.0 GitHub_M 2026-09-23 raw ·
CVE-2026-66069 RabbitMQ: Monitoring-tag DELETE of auth-attempt metrics LOW 2.3 GitHub_M 2026-09-23 raw ·
CVE-2026-67404 RabbitMQ: OAuth2 silent verify_none fallback for JWKS fetch CRITICAL 9.2 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-67220 RabbitMQ: JMS topic exchange erl_scan atom exhaustion MEDIUM 6.0 GitHub_M 2026-09-23 raw ·
CVE-2026-67224 RabbitMQ: Admin path-traversal write via trace name LOW 2.1 GitHub_M 2026-09-23 raw ·
CVE-2026-66077 RabbitMQ: Stored XSS via TLS peer-certificate DN in management UI HIGH 7.3 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-66079 RabbitMQ: Pre-auth AMQP 1.0 array32 zero-width element DoS HIGH 8.2 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-96552 sfturing hosp_order User Password MD5.java MD5.getMD5 hash without salt LOW 2.3 3.1 VulDB 2026-09-23 raw ·
CVE-2026-66070 RabbitMQ: CORS * reflects Origin with Allow-Credentials HIGH 7.6 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-67238 RabbitMQ: Atom-table exhaustion via reply-to queue name decoding HIGH 7.1 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-66076 RabbitMQ: Cross-vhost quorum-queue status and stream tracking disclosure LOW 2.3 GitHub_M 2026-09-23 raw ·
CVE-2026-87899 CVE-2026-87899 CRITICAL 9.4 hackerone 2026-09-23 ⚠ Threat raw ·
CVE-2026-68492 CVE-2026-68492 HIGH 8.7 hackerone 2026-09-23 ⚠ Threat raw ·
CVE-2026-68490 CVE-2026-68490 HIGH 8.2 hackerone 2026-09-23 ⚠ Threat raw ·
CVE-2026-87900 CVE-2026-87900 CRITICAL 9.4 hackerone 2026-09-23 ⚠ Threat raw ·
CVE-2026-87898 CVE-2026-87898 CRITICAL 9.4 hackerone 2026-09-23 ⚠ Threat raw ·
CVE-2026-96551 sfturing hosp_order CommonUserController.java cross-site request forgery MEDIUM 5.3 4.3 VulDB 2026-09-23 raw ·
CVE-2026-84724 Automation-controller: automation-controller: systemjob extra_vars.days argument injection into uncontainerized control-… MEDIUM 6.6 6.6 redhat 2026-09-23 raw ·
CVE-2026-84721 Automation-controller: automation-controller: email notification backend allows ssrf via user-controlled smtp host/port … MEDIUM 6.4 6.4 redhat 2026-09-23 raw ·
CVE-2026-84720 Automation-controller: automation-controller: workflowjobnode.ancestor_artifacts lacks prevent_search, exposing no_log s… MEDIUM 6.5 6.5 redhat 2026-09-23 raw ·
CVE-2026-84718 Automation-controller: automation-controller: client ip spoofing in audit/access logs via unrestricted x-forwarded-for t… MEDIUM 4.3 4.3 redhat 2026-09-23 raw ·
CVE-2026-84717 Automation-controller: automation-controller: unauthenticated 200-vs-403 oracle in bitbucket data center webhook receive… MEDIUM 5.3 5.3 redhat 2026-09-23 raw ·
CVE-2026-84716 Automation-controller: automation-controller: instance install_bundle issues 10-year, non-revocable receptor mesh-ca cer… MEDIUM 6.6 6.6 redhat 2026-09-23 raw ·
CVE-2026-84713 Automation-controller: automation-controller: notification.recipients/subject/error lack prevent_search, allowing zero-p… MEDIUM 6.5 6.5 redhat 2026-09-23 raw ·
CVE-2026-84712 Automation-controller: automation-controller: unauthenticated /api/v2/ping/ discloses automation-mesh instance topology … MEDIUM 5.3 5.3 redhat 2026-09-23 raw ·
CVE-2026-96889 Librsvg: use-after-free when xml includes have duplicated entities HIGH 7.8 7.8 redhat 2026-09-23 ⚠ Threat raw ·
CVE-2026-85475 Automation-controller: automation-controller-container: automation-controller: rsyslog configuration injection via log_a… HIGH 7.2 7.2 redhat 2026-09-23 ⚠ Threat raw ·
CVE-2026-84719 Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitizer omits instance_groups autho… CRITICAL 9.9 9.9 redhat 2026-09-23 ⚠ Threat raw ·
CVE-2026-84714 Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jinja template injection into ad-… HIGH 7.1 7.1 redhat 2026-09-23 ⚠ Threat raw ·
CVE-2026-84706 Automation-controller: automation-controller-container: automation-controller: credential type env-injector deny-list om… HIGH 7.6 7.6 redhat 2026-09-23 ⚠ Threat raw ·
CVE-2026-75884 Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in container groups CRITICAL 9.1 9.1 redhat 2026-09-23 ⚠ Threat raw ·
CVE-2026-96550 sfturing hosp_order MailUtil.java getProperties cleartext transmission MEDIUM 6.3 3.7 VulDB 2026-09-23 raw ·
CVE-2026-96826 WordPress W4 Post List plugin <= 3.0.6 - SQL Injection vulnerability HIGH 7.6 7.6 Patchstack 2026-09-23 ⚠ Threat raw ·
CVE-2026-82405 Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of… HIGH 8.7 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-82409 Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery HIGH 8.4 GitHub_M 2026-09-23 ⚠ Threat raw ·