s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVEs

Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.

Reset

229687 CVEs matched. Showing 1401–1450 (page 29 of 4594).

HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.

Click a column header to sort all results; click the active column again to reverse.

CVE-ID ↕ Title ↕ Severity ↕ Score (overview) ↕ NVD Score MSRC Score CNA ↕ Published ↕ Remediations Threat Source
CVE-2026-96556 Neethuharii CafeManagement AddCashierCode.php addcashier improper authorization MEDIUM 6.9 7.3 — VulDB 2026-09-23 10 — raw · ⬇
CVE-2026-66072 RabbitMQ: Atom table exhaustion via stream `chunk_selector` MEDIUM 6.0 — — GitHub_M 2026-09-23 10 — raw · ⬇
CVE-2026-66067 RabbitMQ: Stream protocol skips per vhost per user connection limits MEDIUM 6.0 — — GitHub_M 2026-09-23 10 — raw · ⬇
CVE-2026-66069 RabbitMQ: Monitoring-tag DELETE of auth-attempt metrics LOW 2.3 — — GitHub_M 2026-09-23 10 — raw · ⬇
CVE-2026-67404 RabbitMQ: OAuth2 silent verify_none fallback for JWKS fetch CRITICAL 9.2 — — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-67220 RabbitMQ: JMS topic exchange erl_scan atom exhaustion MEDIUM 6.0 — — GitHub_M 2026-09-23 10 — raw · ⬇
CVE-2026-67224 RabbitMQ: Admin path-traversal write via trace name LOW 2.1 — — GitHub_M 2026-09-23 10 — raw · ⬇
CVE-2026-66077 RabbitMQ: Stored XSS via TLS peer-certificate DN in management UI HIGH 7.3 — — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-66079 RabbitMQ: Pre-auth AMQP 1.0 array32 zero-width element DoS HIGH 8.2 — — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-96552 sfturing hosp_order User Password MD5.java MD5.getMD5 hash without salt LOW 2.3 3.1 — VulDB 2026-09-23 10 — raw · ⬇
CVE-2026-66070 RabbitMQ: CORS * reflects Origin with Allow-Credentials HIGH 7.6 — — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-67238 RabbitMQ: Atom-table exhaustion via reply-to queue name decoding HIGH 7.1 — — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-66076 RabbitMQ: Cross-vhost quorum-queue status and stream tracking disclosure LOW 2.3 — — GitHub_M 2026-09-23 10 — raw · ⬇
CVE-2026-87899 CVE-2026-87899 CRITICAL 9.4 — — hackerone 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-68492 CVE-2026-68492 HIGH 8.7 — — hackerone 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-68490 CVE-2026-68490 HIGH 8.2 — — hackerone 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-87900 CVE-2026-87900 CRITICAL 9.4 — — hackerone 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-87898 CVE-2026-87898 CRITICAL 9.4 — — hackerone 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-96551 sfturing hosp_order CommonUserController.java cross-site request forgery MEDIUM 5.3 4.3 — VulDB 2026-09-23 10 — raw · ⬇
CVE-2026-84724 Automation-controller: automation-controller: systemjob extra_vars.days argument injection into uncontainerized control-… MEDIUM 6.6 6.6 — redhat 2026-09-23 10 — raw · ⬇
CVE-2026-84721 Automation-controller: automation-controller: email notification backend allows ssrf via user-controlled smtp host/port … MEDIUM 6.4 6.4 — redhat 2026-09-23 10 — raw · ⬇
CVE-2026-84720 Automation-controller: automation-controller: workflowjobnode.ancestor_artifacts lacks prevent_search, exposing no_log s… MEDIUM 6.5 6.5 — redhat 2026-09-23 10 — raw · ⬇
CVE-2026-84718 Automation-controller: automation-controller: client ip spoofing in audit/access logs via unrestricted x-forwarded-for t… MEDIUM 4.3 4.3 — redhat 2026-09-23 10 — raw · ⬇
CVE-2026-84717 Automation-controller: automation-controller: unauthenticated 200-vs-403 oracle in bitbucket data center webhook receive… MEDIUM 5.3 5.3 — redhat 2026-09-23 10 — raw · ⬇
CVE-2026-84716 Automation-controller: automation-controller: instance install_bundle issues 10-year, non-revocable receptor mesh-ca cer… MEDIUM 6.6 6.6 — redhat 2026-09-23 10 — raw · ⬇
CVE-2026-84713 Automation-controller: automation-controller: notification.recipients/subject/error lack prevent_search, allowing zero-p… MEDIUM 6.5 6.5 — redhat 2026-09-23 10 — raw · ⬇
CVE-2026-84712 Automation-controller: automation-controller: unauthenticated /api/v2/ping/ discloses automation-mesh instance topology … MEDIUM 5.3 5.3 — redhat 2026-09-23 10 — raw · ⬇
CVE-2026-96889 Librsvg: use-after-free when xml includes have duplicated entities HIGH 7.8 7.8 — redhat 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-85475 Automation-controller: automation-controller-container: automation-controller: rsyslog configuration injection via log_a… HIGH 7.2 7.2 — redhat 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-84719 Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitizer omits instance_groups autho… CRITICAL 9.9 9.9 — redhat 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-84714 Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jinja template injection into ad-… HIGH 7.1 7.1 — redhat 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-84706 Automation-controller: automation-controller-container: automation-controller: credential type env-injector deny-list om… HIGH 7.6 7.6 — redhat 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-75884 Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in container groups CRITICAL 9.1 9.1 — redhat 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-96550 sfturing hosp_order MailUtil.java getProperties cleartext transmission MEDIUM 6.3 3.7 — VulDB 2026-09-23 10 — raw · ⬇
CVE-2026-96826 WordPress W4 Post List plugin <= 3.0.6 - SQL Injection vulnerability HIGH 7.6 7.6 — Patchstack 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-82405 Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of… HIGH 8.7 — — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-82409 Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery HIGH 8.4 — — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-82407 Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS HIGH 7.0 — — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-86065 Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node… HIGH 7.5 7.5 — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-86064 Klever-Go: /log controls global node logging HIGH 8.6 8.6 — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-82406 Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace HIGH 7.1 — — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-84691 Automation-controller: automation-controller-container: automation-controller: format string injection in the api 4xx er… HIGH 8.7 8.7 — redhat 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-84683 Automation-controller: automation-controller-container: automation-controller: stored cross-site scripting in the job st… HIGH 8.7 8.7 — redhat 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-94183 Address bar spoofing risk in affected Android versions of Arc Search HIGH 7.4 7.4 — BCNY 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-96549 sfturing hosp_order CommonUserServiceImpl.java cleartext storage MEDIUM 4.8 3.3 — VulDB 2026-09-23 10 — raw · ⬇
CVE-2026-93421 Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint MEDIUM 5.3 — — GitHub_M 2026-09-23 10 — raw · ⬇
CVE-2026-96770 s2s-proxy accepts untrusted client certificates CRITICAL 9.3 — — Temporal 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-77602 OpenC3 COSMOS: Authenticated remote code execution via the user-writable config overlay (table definitions, cmd/tlm defi… CRITICAL 9.9 9.9 — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-94181 Address Bar Spoof Risk; Missing Fullscreen Notification via Select Element HIGH 7.4 7.4 — BCNY 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-77394 OpenC3 COSMOS: Stored, cross-user XSS via Telemetry screen BUTTON widget HIGH 7.6 7.6 — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇