s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVEs

Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.

Reset

228318 CVEs matched. Showing 101–150 (page 3 of 4567).

HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.

Click a column header to sort all results; click the active column again to reverse.

CVE-ID Title Severity Score (overview) NVD Score MSRC Score CNA Published Remediations Threat Source
CVE-2026-82407 Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS HIGH 7.0 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-86065 Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node… HIGH 7.5 7.5 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-86064 Klever-Go: /log controls global node logging HIGH 8.6 8.6 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-82406 Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace HIGH 7.1 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-84691 Automation-controller: automation-controller-container: automation-controller: format string injection in the api 4xx er… HIGH 8.7 8.7 redhat 2026-09-23 ⚠ Threat raw ·
CVE-2026-84683 Automation-controller: automation-controller-container: automation-controller: stored cross-site scripting in the job st… HIGH 8.7 8.7 redhat 2026-09-23 ⚠ Threat raw ·
CVE-2026-94183 Address bar spoofing risk in affected Android versions of Arc Search HIGH 7.4 7.4 BCNY 2026-09-23 ⚠ Threat raw ·
CVE-2026-96549 sfturing hosp_order CommonUserServiceImpl.java cleartext storage MEDIUM 4.8 3.3 VulDB 2026-09-23 raw ·
CVE-2026-93421 Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint MEDIUM 5.3 GitHub_M 2026-09-23 raw ·
CVE-2026-96770 s2s-proxy accepts untrusted client certificates CRITICAL 9.3 Temporal 2026-09-23 ⚠ Threat raw ·
CVE-2026-77602 OpenC3 COSMOS: Authenticated remote code execution via the user-writable config overlay (table definitions, cmd/tlm defi… CRITICAL 9.9 9.9 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-94181 Address Bar Spoof Risk; Missing Fullscreen Notification via Select Element HIGH 7.4 7.4 BCNY 2026-09-23 ⚠ Threat raw ·
CVE-2026-77394 OpenC3 COSMOS: Stored, cross-user XSS via Telemetry screen BUTTON widget HIGH 7.6 7.6 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-77601 OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting HIGH 8.8 8.8 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-96872 WikiLambda public function execution bypasses the unsaved-code permission through nested Z825 compositions LOW 2.9 wikimedia-foundation 2026-09-23 raw ·
CVE-2026-84499 Automation-controller: automation-controller-container: automation-controller: write-only survey password recovered in p… HIGH 7.7 7.7 redhat 2026-09-23 ⚠ Threat raw ·
CVE-2026-84502 Automation-controller: automation-controller-container: automation-controller: project scm_url argument injection into `… CRITICAL 9.9 9.9 redhat 2026-09-23 ⚠ Threat raw ·
CVE-2026-61695 Wire Swift runtime: negative LENGTH_DELIMITED length in skipGroup() crashes any protobuf-decoding service HIGH 7.5 7.5 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-90903 Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Stor… HIGH 7.2 Joomla 2026-09-23 ⚠ Threat raw ·
CVE-2026-90901 Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extens… HIGH 8.6 Joomla 2026-09-23 ⚠ Threat raw ·
CVE-2026-90905 Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension… HIGH 7.2 Joomla 2026-09-23 ⚠ Threat raw ·
CVE-2026-84474 Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege esc… CRITICAL 9.9 9.9 redhat 2026-09-23 ⚠ Threat raw ·
CVE-2026-59990 Jawn: Uncontrolled nesting depth in JSON parser HIGH 7.5 7.5 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-82368 CVE-2026-82368 HIGH 8.7 brocade 2026-09-23 ⚠ Threat raw ·
CVE-2026-90902 Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extensio… HIGH 8.2 Joomla 2026-09-23 ⚠ Threat raw ·
CVE-2026-61814 Jawn: Quadratic parsing effort in AsyncParser HIGH 7.5 7.5 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-90904 Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store ext… HIGH 8.6 Joomla 2026-09-23 ⚠ Threat raw ·
CVE-2026-90899 Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.… HIGH 8.2 Joomla 2026-09-23 ⚠ Threat raw ·
CVE-2026-84486 Automation-controller: automation-controller-container: automation-controller: unauthenticated debug scheduler-trigger e… HIGH 8.2 8.2 redhat 2026-09-23 ⚠ Threat raw ·
CVE-2026-76087 Formie: Unauthenticated users can overwrite incomplete submissions via submit action HIGH 8.2 8.2 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-90900 Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Stor… MEDIUM 5.3 Joomla 2026-09-23 raw ·
CVE-2026-76086 Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials HIGH 8.5 8.5 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-96548 sfturing hosp_order jdbc.properties hard-coded credentials MEDIUM 6.3 5.6 VulDB 2026-09-23 raw ·
CVE-2026-96546 Gimp: gimp: one-byte out-of-bounds heap read in the uncompressed dds loader LOW 2.5 2.5 redhat 2026-09-23 raw ·
CVE-2026-71465 Automation-controller: automation-controller-container: automation-controller: ad-hoc command limit field allows cli arg… LOW 3.1 3.1 redhat 2026-09-23 raw ·
CVE-2026-71464 Automation-controller: automation-controller-container: automation-controller: schedule and workflowjobtemplatenode scm_… LOW 3.1 3.1 redhat 2026-09-23 raw ·
CVE-2026-71463 Automation-controller: automation-controller-container: automation-controller: notification template jinja whitelist byp… LOW 2.7 2.7 redhat 2026-09-23 raw ·
CVE-2026-96545 Gimp: gimp: out-of-bounds heap read in the 4bpp tim image loader MEDIUM 4.4 4.4 redhat 2026-09-23 raw ·
CVE-2026-76089 Formie: Missing authorization on sent notification resend modal exposes submission PII HIGH 7.7 7.7 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-82356 Imprivata EAM: Unrotatable X.509 RSA Key Pair in Production certcc 2026-09-23 raw ·
CVE-2026-71462 Automation-controller: automation-controller-container: automation-controller: custom_venv_path setting provides filesys… MEDIUM 4.1 4.1 redhat 2026-09-23 raw ·
CVE-2026-71461 Automation-controller: automation-controller-container: automation-controller: verbose internal exception … MEDIUM 4.3 4.3 redhat 2026-09-23 raw ·
CVE-2026-71460 Automation-controller: automation-controller-container: automation-controller: any authenticated user reads red hat subs… MEDIUM 4.3 4.3 redhat 2026-09-23 raw ·
CVE-2026-76648 Automation-controller: automation-controller-container: aap controller: copyapiview.post() missing read … HIGH 8.5 8.5 redhat 2026-09-23 ⚠ Threat raw ·
CVE-2026-92692 Sulu: JCR-SQL2 injection via `categories` query parameter (unauthenticated) MEDIUM 6.9 GitHub_M 2026-09-23 raw ·
CVE-2026-77423 JLine: ReDoS in Built-in Less Viewer Search HIGH 7.5 7.5 GitHub_M 2026-09-23 ⚠ Threat raw ·
CVE-2026-95604 WordPress Loops & Logic plugin <= 4.2.4 - Broken Access Control vulnerability HIGH 7.5 7.5 Patchstack 2026-09-23 ⚠ Threat raw ·
CVE-2026-95603 WordPress Reycob Product Import Export plugin <= 2.3.0 - PHP Object Injection vulnerability HIGH 7.2 7.2 Patchstack 2026-09-23 ⚠ Threat raw ·
CVE-2026-95602 WordPress YITH WooCommerce Request A Quote plugin < 4.46.1 - Insecure Direct Object References (IDOR) vulnerability MEDIUM 6.5 6.5 Patchstack 2026-09-23 raw ·
CVE-2026-95601 WordPress Product Filter by WBW plugin <= 3.1.7 - SQL Injection vulnerability CRITICAL 9.3 9.3 Patchstack 2026-09-23 ⚠ Threat raw ·