s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVEs

Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.

Reset

228874 CVEs matched. Showing 1101–1150 (page 23 of 4578).

HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.

Click a column header to sort all results; click the active column again to reverse.

CVE-ID ↕ Title ↕ Severity ↕ Score (overview) ↕ NVD Score MSRC Score CNA ↕ Published ↕ Remediations Threat Source
CVE-2026-76910 Unleash: Clone-feature lets a user copy a feature from a project they cannot read MEDIUM 5.3 — — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-95815 OpenClaw iOS before 2026.8.11 Credential Exposure via Deep-Link URL Logging HIGH 7.2 6.3 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-95814 Vaultwarden through 1.37.3 Authorization Bypass via Missing Status Check HIGH 8.6 8.1 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-95813 e621ng before 26.09.16 Open Redirect via URL Parameters MEDIUM 5.3 6.1 — VulnCheck 2026-09-22 10 — raw · ⬇
CVE-2026-95812 ClipBucket v5 before 5.5.3-#182 Reflected XSS via Query Parameters MEDIUM 5.3 6.1 — VulnCheck 2026-09-22 10 — raw · ⬇
CVE-2026-76909 Unleash: CR-approval email renders user-controlled raw HTML LOW 2.1 — — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-62364 wlc may disclose API tokens to project-configured URLs LOW 2.3 2.3 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-94450 Potential denial of service when configured to send Retry packets in s2n-quic HIGH 8.7 7.5 — AMZN 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-79767 Gardener: Authorization Bypass via Group Subject Injection MEDIUM 5.5 5.5 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-61570 MPXJ: XXE Vulnerability in MerlinReader HIGH 7.5 7.5 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-65829 MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers MEDIUM 5.3 5.3 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-77322 SIPGO: DoS via unvalidated WebSocket frame length HIGH 7.5 7.5 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-58268 SIPGO: DoS via unvalidated Content-Length in the stream parser HIGH 7.5 7.5 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-87121 Out-of-bounds write in lwIP TCP/IP Stack MQTT Client Application CRITICAL 9.3 9.8 — icscert 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-83805 Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of schedul… MEDIUM 6.4 6.4 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-83801 Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text MEDIUM 5.4 5.4 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-63104 Kaneo 2.3.12 < 2.12.2 Missing Authorization via Bulk Task Endpoint HIGH 7.2 8.1 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-47116 LTSecurity LTK3500SF Hard-coded Credentials via Telnet/SSH CRITICAL 9.3 9.8 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-94574 CVE-2026-94574 — — — — certcc 2026-09-22 10 — raw · ⬇
CVE-2026-89281 CVE-2026-89281 — — — — certcc 2026-09-22 10 — raw · ⬇
CVE-2026-89282 CVE-2026-89282 — — — — certcc 2026-09-22 10 — raw · ⬇
CVE-2026-62985 request-filtering-agent: Synchronous throw from createConnection() for literal private-IP hosts bypasses req.on('error')… HIGH 7.5 7.5 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-28325 SolarWinds Observability Self-Hosted Unauthenticated Remote Code Execution Vulnerability HIGH 8.8 8.8 — SolarWinds 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-76717 Unauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE Networking Analytics and Location Engine (A… MEDIUM 5.3 5.3 — hpe 2026-09-22 10 — raw · ⬇
CVE-2026-76716 Unauthenticated Remote Unauthorized Access and Denial of Service Vulnerabilities in HPE Networking Analytics and Locatio… MEDIUM 5.3 5.3 — hpe 2026-09-22 10 — raw · ⬇
CVE-2026-76715 Unauthenticated Man-in-the-Middle Attach Leads to Remote Code Execution Vulnerability in HPE Networking Analytics and Lo… HIGH 7.1 7.1 — hpe 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-76714 Authenticated Remote Code Execution with Elevated Privileges Vulnerability in HPE Networking Analytics and Location Engi… HIGH 7.2 7.2 — hpe 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-76713 Authenticated Remote File System Access Vulnerability in HPE Networking Analytics and Location Engine (ALE) HIGH 7.2 7.2 — hpe 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-76712 Unauthenticated Remote Unauthorized Access, Information Disclosure, and Denial of Service Vulnerabilities in HPE Network… HIGH 7.3 7.3 — hpe 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-76711 Unauthenticated Remote Data Injection Vulnerability in HPE Networking Analytics and Location Engine (ALE) HIGH 7.5 7.5 — hpe 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-76710 Unauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE Networking Analytics and Location Engine (A… HIGH 7.5 7.5 — hpe 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-76709 Unauthenticated Remote Arbitrary File Write Vulnerability in HPE Networking Analytics and Location Engine (ALE) CRITICAL 9.8 9.8 — hpe 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-76708 Unauthenticated Remote Unauthorized Access Vulnerability in HPE Networking Analytics and Location Engine (ALE) CRITICAL 9.8 9.8 — hpe 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-59991 psd-tools: Uncontrolled memory allocation in psd-tools composite/numpy via crafted PSD geometry HIGH 7.5 7.5 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-28324 SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability CRITICAL 9.8 9.8 — SolarWinds 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-63628 mppx: Gas Draining with access list MEDIUM 6.9 — — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-63627 mppx: Gas Draining with padding MEDIUM 6.9 — — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-91129 Home Assistant: mDNS Server-Side Request Forgery MEDIUM 5.4 5.4 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-91130 Home Assistant: XSS in Statistics Graph Card CRITICAL 9.3 — — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-57149 plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection CRITICAL 9.9 9.9 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-63386 js-toml: Uncontrolled recursion in `load()` causes `RangeError` (stack exhaustion) on deeply nested input MEDIUM 5.3 5.3 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-77399 icalendar: Denial of service via unbounded VALARM REPEAT expansion MEDIUM 6.5 6.5 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-84395 Premiere Pro | Server-Side Request Forgery (SSRF) (CWE-918) HIGH 7.1 7.1 — adobe 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-83963 Substance3D - Modeler | Out-of-bounds Write (CWE-787) HIGH 7.8 7.8 — adobe 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-81998 Substance3D - Modeler | Out-of-bounds Write (CWE-787) HIGH 7.8 7.8 — adobe 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-83962 Substance3D - Modeler | Stack-based Buffer Overflow (CWE-121) HIGH 7.8 7.8 — adobe 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-79906 Substance3D - Modeler | Out-of-bounds Write (CWE-787) HIGH 7.8 7.8 — adobe 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-94462 Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR) HIGH 7.1 7.1 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-75743 Adobe Experience Manager Forms JEE | Cross-Site Request Forgery (CSRF) (CWE-352) HIGH 7.1 7.1 — adobe 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-75745 Adobe Experience Manager Forms JEE | Incorrect Authorization (CWE-863) CRITICAL 10.0 10.0 — adobe 2026-09-22 10 ⚠ Threat raw · ⬇