s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVEs

Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.

Reset

229687 CVEs matched. Showing 1201–1250 (page 25 of 4594).

HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.

Click a column header to sort all results; click the active column again to reverse.

CVE-ID ↕ Title ↕ Severity ↕ Score (overview) ↕ NVD Score MSRC Score CNA ↕ Published ↕ Remediations Threat Source
CVE-2026-65422 CVE-2026-65422 MEDIUM 6.5 — — Genetec 2026-09-24 10 — raw · ⬇
CVE-2026-77703 SSH Host Key Verification Bypass in HAVELSAN's Liman Render Engine MEDIUM 5.9 — — TR-CERT 2026-09-24 10 — raw · ⬇
CVE-2026-97404 CVE-2026-97404 CRITICAL 9.2 — — mitre 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-82094 DataStage on Cloud Pak for Data has several vulnerabilities HIGH 7.1 7.1 — ibm 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-82093 DataStage on Cloud Pak for Data has several vulnerabilities HIGH 8.8 — — ibm 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-81552 DataStage on Cloud Pak for Data has several vulnerabilities HIGH 8.8 8.8 — ibm 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-81549 DataStage on Cloud Pak for Data has several vulnerabilities CRITICAL 9.6 9.6 — ibm 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-81548 DataStage on Cloud Pak for Data has several vulnerabilities HIGH 8.8 8.8 — ibm 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-81547 DataStage on Cloud Pak for Data has several vulnerabilities HIGH 8.8 8.8 — ibm 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-81545 DataStage on Cloud Pak for Data has several vulnerabilities HIGH 8.8 — — ibm 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-81539 DataStage on Cloud Pak for Data has several vulnerabilities HIGH 8.8 8.8 — ibm 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-77874 IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities HIGH 8.6 — — ibm 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-77825 IBM ContextForge MCP Gateway is affected by path traversal MEDIUM 4.9 — — ibm 2026-09-24 10 — raw · ⬇
CVE-2026-56736 phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submission HIGH 8.2 — — GitHub_M 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-6544 Multiple Vulnerabilities in IBM Concert Software MEDIUM 6.2 6.2 — ibm 2026-09-24 10 — raw · ⬇
CVE-2026-12559 Stored Cross-Site Scripting (XSS) in OpenText Vendor Invoice Management for SAP Solutions Capture Validation Application HIGH 7.3 — — OpenText 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-19492 This Power System update is being released to address LOW 3.2 — — ibm 2026-09-24 10 — raw · ⬇
CVE-2026-18870 This Power System update is being released to address MEDIUM 4.3 — — ibm 2026-09-24 10 — raw · ⬇
CVE-2026-90481 CVE-2026-90481 CRITICAL 9.2 — — mitre 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-18857 This Power System update is being released to address LOW 3.4 — — ibm 2026-09-24 10 — raw · ⬇
CVE-2026-18104 IBM Db2 Mirror for i is vulnerable to obtain sensitive information [] LOW 3.3 3.3 — ibm 2026-09-24 10 — raw · ⬇
CVE-2026-17511 This Power System update is being released to address LOW 3.4 3.4 — ibm 2026-09-24 10 — raw · ⬇
CVE-2026-17504 This Power System update is being released to address MEDIUM 5.1 — — ibm 2026-09-24 10 — raw · ⬇
CVE-2026-17503 This Power System update is being released to address MEDIUM 5.1 5.1 — ibm 2026-09-24 10 — raw · ⬇
CVE-2026-17413 This Power System update is being released to address MEDIUM 5.1 — — ibm 2026-09-24 10 — raw · ⬇
CVE-2026-97062 Aureus ERP through 1.6.0 Stored XSS via SVG File Upload MEDIUM 5.1 — — VulnCheck 2026-09-24 10 — raw · ⬇
CVE-2026-97061 Black Candy through 3.2.1 Information Disclosure via Playlist Search MEDIUM 5.3 — — VulnCheck 2026-09-24 10 — raw · ⬇
CVE-2026-97059 DCMTK through 3.7.0 Heap Over-read via NumberOfFrames HIGH 8.8 — — VulnCheck 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-97058 sprintf-js through 1.1.3 Denial of Service via Unbounded Precision MEDIUM 6.9 5.3 — VulnCheck 2026-09-24 10 — raw · ⬇
CVE-2026-97057 redis-parser through 3.0.0 Denial of Service via Invalid Array Length HIGH 8.7 — — VulnCheck 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-77798 Velociraptor Authenticated Denial of Service MEDIUM 6.5 6.5 — rapid7 2026-09-24 10 — raw · ⬇
CVE-2026-77797 Velociraptor Prefetch parser out of bounds LOW 3.6 3.6 — rapid7 2026-09-24 10 — raw · ⬇
CVE-2026-97360 HFS2 2.4.0 Unauthenticated Arbitrary File Read/Write via Template Engine CRITICAL 10.0 10.0 — VulnCheck 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-97359 HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection CRITICAL 10.0 — — VulnCheck 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-95521 Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when installing a source rpm HIGH 7.8 — — redhat 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-95519 Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify manifest flows) HIGH 7.8 7.8 — redhat 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-91187 Improper Verification of Cryptographic Signature in dashbit nimble_zta Cloudflare strategy CRITICAL 9.3 — — EEF 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-19072 Velociraptor Investigator reaches SuperUser via hunt EffectivePrincipal CRITICAL 9.9 9.9 — rapid7 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-88916 Admin Access Bypass via Header Fallback in TÜBİTAK ULAKBİM's UlakPDF MEDIUM 6.8 — — TR-CERT 2026-09-24 10 — raw · ⬇
CVE-2026-88907 SAML ePPN Attribute Validation Bypass in TÜBİTAK ULAKBİM's UlakPDF HIGH 7.4 — — TR-CERT 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-94416 Aap-gateway: aap-gateway: authorization bypass via workload identity token forgery MEDIUM 6.8 6.8 — redhat 2026-09-24 10 — raw · ⬇
CVE-2026-97182 halo-dev Halo SpEL ReplyNotificationSubscriptionHelper.java neutralization MEDIUM 6.9 7.3 — VulDB 2026-09-24 10 — raw · ⬇
CVE-2026-96515 Command Injection Vulnerability in Netlink ICT HG323RW Router HIGH 8.6 — — CERT-In 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-19532 Path Traversal in HAVELSAN's Liman MYS MEDIUM 5.3 5.3 — TR-CERT 2026-09-24 10 — raw · ⬇
CVE-2026-16302 Spectra Legacy – Gutenberg Blocks <= 2.20.0 - Authenticated (Contributor+) Sensitive Information Exposure MEDIUM 4.3 4.3 — Wordfence 2026-09-24 10 — raw · ⬇
CVE-2026-4806 Custom Thank You Page for WooCommerce <= 1.1.2 - Missing Authorization to Unauthenticated Settings Export and Settings R… MEDIUM 6.5 6.5 — Wordfence 2026-09-24 10 — raw · ⬇
CVE-2026-3253 MailerLite – Signup forms (official) <= 1.7.21 - Missing Authorization to Authenticated (Contributor+) Form Creation and… MEDIUM 4.3 4.3 — Wordfence 2026-09-24 10 — raw · ⬇
CVE-2026-97311 Keycloak-services: keycloak-services: admin rest api role-groups endpoint discloses groups without authorization MEDIUM 4.3 — — redhat 2026-09-24 10 — raw · ⬇
CVE-2026-7169 Uncontrolled Search Path Element in Evope Collector HIGH 7.5 — — INCIBE 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-4638 Plaintext Password Disclosure via VBScript Sensor Error Message in Paessler PRTG Network Monitor HIGH 7.1 — — SEC-VLab 2026-09-24 10 ⚠ Threat raw · ⬇