CVEs
Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.
228318 CVEs matched. Showing 51–100 (page 2 of 4567).
HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.
Click a column header to sort all results; click the active column again to reverse.
| CVE-ID ↕ | Title ↕ | Severity ↕ | Score (overview) ↕ | NVD Score | MSRC Score | CNA ↕ | Published ↕ | Remediations | Threat | Source |
|---|---|---|---|---|---|---|---|---|---|---|
CVE-2026-66074 |
RabbitMQ: ReDoS via management API ?name= filter | MEDIUM | 6.0 | — | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-82369 |
Insufficient input sanitization of shell metacharacters in Brocade SANnav before 3.0.1a | HIGH | 8.6 | — | — | brocade | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-6718 |
Multiple Vulnerabilities in IBM Concert Software | MEDIUM | 6.2 | 6.2 | — | ibm | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-67232 |
RabbitMQ: Web-MQTT decompression bomb | HIGH | 8.2 | — | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-67405 |
RabbitMQ: CSWSH on Web-STOMP / Web-MQTT (no Origin validation) | MEDIUM | 5.3 | — | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-66075 |
RabbitMQ: Monitoring-tag user can restart federation links | LOW | 2.3 | — | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-67219 |
RabbitMQ: Consistent-hash exchange unbounded weight | MEDIUM | 6.0 | — | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-67228 |
RabbitMQ: Atom exhaustion: to_atom on runtime-parameter component | MEDIUM | 6.9 | — | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-67235 |
RabbitMQ: AMQP 0-9-1 body assembly never validates accumulated size | HIGH | 7.1 | — | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-66068 |
RabbitMQ: Shovel DEBUG log of full state exposes decrypted URIs | MEDIUM | 5.6 | — | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-67229 |
RabbitMQ: Admin-only atom exhaustion: atomize_keys on vhost metadata | MEDIUM | 6.9 | — | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-66080 |
RabbitMQ: Super-stream partitions unbounded allocation | MEDIUM | 5.9 | — | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-67240 |
RabbitMQ: ReDoS via AMQP 1.0 SQL filter LIKE wildcard | LOW | 2.3 | — | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-96556 |
Neethuharii CafeManagement AddCashierCode.php addcashier improper authorization | MEDIUM | 6.9 | 7.3 | — | VulDB | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-66072 |
RabbitMQ: Atom table exhaustion via stream `chunk_selector` | MEDIUM | 6.0 | — | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-66067 |
RabbitMQ: Stream protocol skips per vhost per user connection limits | MEDIUM | 6.0 | — | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-66069 |
RabbitMQ: Monitoring-tag DELETE of auth-attempt metrics | LOW | 2.3 | — | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-67404 |
RabbitMQ: OAuth2 silent verify_none fallback for JWKS fetch | CRITICAL | 9.2 | — | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-67220 |
RabbitMQ: JMS topic exchange erl_scan atom exhaustion | MEDIUM | 6.0 | — | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-67224 |
RabbitMQ: Admin path-traversal write via trace name | LOW | 2.1 | — | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-66077 |
RabbitMQ: Stored XSS via TLS peer-certificate DN in management UI | HIGH | 7.3 | — | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-66079 |
RabbitMQ: Pre-auth AMQP 1.0 array32 zero-width element DoS | HIGH | 8.2 | — | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-96552 |
sfturing hosp_order User Password MD5.java MD5.getMD5 hash without salt | LOW | 2.3 | 3.1 | — | VulDB | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-66070 |
RabbitMQ: CORS * reflects Origin with Allow-Credentials | HIGH | 7.6 | — | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-67238 |
RabbitMQ: Atom-table exhaustion via reply-to queue name decoding | HIGH | 7.1 | — | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-66076 |
RabbitMQ: Cross-vhost quorum-queue status and stream tracking disclosure | LOW | 2.3 | — | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-87899 |
CVE-2026-87899 | CRITICAL | 9.4 | — | — | hackerone | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-68492 |
CVE-2026-68492 | HIGH | 8.7 | — | — | hackerone | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-68490 |
CVE-2026-68490 | HIGH | 8.2 | — | — | hackerone | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-87900 |
CVE-2026-87900 | CRITICAL | 9.4 | — | — | hackerone | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-87898 |
CVE-2026-87898 | CRITICAL | 9.4 | — | — | hackerone | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-96551 |
sfturing hosp_order CommonUserController.java cross-site request forgery | MEDIUM | 5.3 | 4.3 | — | VulDB | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-84724 |
Automation-controller: automation-controller: systemjob extra_vars.days argument injection into uncontainerized control-… | MEDIUM | 6.6 | 6.6 | — | redhat | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-84721 |
Automation-controller: automation-controller: email notification backend allows ssrf via user-controlled smtp host/port … | MEDIUM | 6.4 | 6.4 | — | redhat | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-84720 |
Automation-controller: automation-controller: workflowjobnode.ancestor_artifacts lacks prevent_search, exposing no_log s… | MEDIUM | 6.5 | 6.5 | — | redhat | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-84718 |
Automation-controller: automation-controller: client ip spoofing in audit/access logs via unrestricted x-forwarded-for t… | MEDIUM | 4.3 | 4.3 | — | redhat | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-84717 |
Automation-controller: automation-controller: unauthenticated 200-vs-403 oracle in bitbucket data center webhook receive… | MEDIUM | 5.3 | 5.3 | — | redhat | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-84716 |
Automation-controller: automation-controller: instance install_bundle issues 10-year, non-revocable receptor mesh-ca cer… | MEDIUM | 6.6 | 6.6 | — | redhat | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-84713 |
Automation-controller: automation-controller: notification.recipients/subject/error lack prevent_search, allowing zero-p… | MEDIUM | 6.5 | 6.5 | — | redhat | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-84712 |
Automation-controller: automation-controller: unauthenticated /api/v2/ping/ discloses automation-mesh instance topology … | MEDIUM | 5.3 | 5.3 | — | redhat | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-96889 |
Librsvg: use-after-free when xml includes have duplicated entities | HIGH | 7.8 | 7.8 | — | redhat | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-85475 |
Automation-controller: automation-controller-container: automation-controller: rsyslog configuration injection via log_a… | HIGH | 7.2 | 7.2 | — | redhat | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-84719 |
Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitizer omits instance_groups autho… | CRITICAL | 9.9 | 9.9 | — | redhat | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-84714 |
Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jinja template injection into ad-… | HIGH | 7.1 | 7.1 | — | redhat | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-84706 |
Automation-controller: automation-controller-container: automation-controller: credential type env-injector deny-list om… | HIGH | 7.6 | 7.6 | — | redhat | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-75884 |
Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in container groups | CRITICAL | 9.1 | 9.1 | — | redhat | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-96550 |
sfturing hosp_order MailUtil.java getProperties cleartext transmission | MEDIUM | 6.3 | 3.7 | — | VulDB | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-96826 |
WordPress W4 Post List plugin <= 3.0.6 - SQL Injection vulnerability | HIGH | 7.6 | 7.6 | — | Patchstack | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-82405 |
Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of… | HIGH | 8.7 | — | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-82409 |
Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery | HIGH | 8.4 | — | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |