CVEs
Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.
228318 CVEs matched. Showing 101–150 (page 3 of 4567).
HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.
Click a column header to sort all results; click the active column again to reverse.
| CVE-ID ↕ | Title ↕ | Severity ↕ | Score (overview) ↕ | NVD Score | MSRC Score | CNA ↕ | Published ↕ | Remediations | Threat | Source |
|---|---|---|---|---|---|---|---|---|---|---|
CVE-2026-82407 |
Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS | HIGH | 7.0 | — | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-86065 |
Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node… | HIGH | 7.5 | 7.5 | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-86064 |
Klever-Go: /log controls global node logging | HIGH | 8.6 | 8.6 | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-82406 |
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace | HIGH | 7.1 | — | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-84691 |
Automation-controller: automation-controller-container: automation-controller: format string injection in the api 4xx er… | HIGH | 8.7 | 8.7 | — | redhat | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-84683 |
Automation-controller: automation-controller-container: automation-controller: stored cross-site scripting in the job st… | HIGH | 8.7 | 8.7 | — | redhat | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-94183 |
Address bar spoofing risk in affected Android versions of Arc Search | HIGH | 7.4 | 7.4 | — | BCNY | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-96549 |
sfturing hosp_order CommonUserServiceImpl.java cleartext storage | MEDIUM | 4.8 | 3.3 | — | VulDB | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-93421 |
Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint | MEDIUM | 5.3 | — | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-96770 |
s2s-proxy accepts untrusted client certificates | CRITICAL | 9.3 | — | — | Temporal | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-77602 |
OpenC3 COSMOS: Authenticated remote code execution via the user-writable config overlay (table definitions, cmd/tlm defi… | CRITICAL | 9.9 | 9.9 | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-94181 |
Address Bar Spoof Risk; Missing Fullscreen Notification via Select Element | HIGH | 7.4 | 7.4 | — | BCNY | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-77394 |
OpenC3 COSMOS: Stored, cross-user XSS via Telemetry screen BUTTON widget | HIGH | 7.6 | 7.6 | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-77601 |
OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting | HIGH | 8.8 | 8.8 | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-96872 |
WikiLambda public function execution bypasses the unsaved-code permission through nested Z825 compositions | LOW | 2.9 | — | — | wikimedia-foundation | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-84499 |
Automation-controller: automation-controller-container: automation-controller: write-only survey password recovered in p… | HIGH | 7.7 | 7.7 | — | redhat | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-84502 |
Automation-controller: automation-controller-container: automation-controller: project scm_url argument injection into `… | CRITICAL | 9.9 | 9.9 | — | redhat | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-61695 |
Wire Swift runtime: negative LENGTH_DELIMITED length in skipGroup() crashes any protobuf-decoding service | HIGH | 7.5 | 7.5 | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-90903 |
Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Stor… | HIGH | 7.2 | — | — | Joomla | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-90901 |
Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extens… | HIGH | 8.6 | — | — | Joomla | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-90905 |
Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension… | HIGH | 7.2 | — | — | Joomla | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-84474 |
Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege esc… | CRITICAL | 9.9 | 9.9 | — | redhat | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-59990 |
Jawn: Uncontrolled nesting depth in JSON parser | HIGH | 7.5 | 7.5 | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-82368 |
CVE-2026-82368 | HIGH | 8.7 | — | — | brocade | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-90902 |
Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extensio… | HIGH | 8.2 | — | — | Joomla | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-61814 |
Jawn: Quadratic parsing effort in AsyncParser | HIGH | 7.5 | 7.5 | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-90904 |
Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store ext… | HIGH | 8.6 | — | — | Joomla | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-90899 |
Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.… | HIGH | 8.2 | — | — | Joomla | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-84486 |
Automation-controller: automation-controller-container: automation-controller: unauthenticated debug scheduler-trigger e… | HIGH | 8.2 | 8.2 | — | redhat | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-76087 |
Formie: Unauthenticated users can overwrite incomplete submissions via submit action | HIGH | 8.2 | 8.2 | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-90900 |
Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Stor… | MEDIUM | 5.3 | — | — | Joomla | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-76086 |
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials | HIGH | 8.5 | 8.5 | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-96548 |
sfturing hosp_order jdbc.properties hard-coded credentials | MEDIUM | 6.3 | 5.6 | — | VulDB | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-96546 |
Gimp: gimp: one-byte out-of-bounds heap read in the uncompressed dds loader | LOW | 2.5 | 2.5 | — | redhat | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-71465 |
Automation-controller: automation-controller-container: automation-controller: ad-hoc command limit field allows cli arg… | LOW | 3.1 | 3.1 | — | redhat | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-71464 |
Automation-controller: automation-controller-container: automation-controller: schedule and workflowjobtemplatenode scm_… | LOW | 3.1 | 3.1 | — | redhat | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-71463 |
Automation-controller: automation-controller-container: automation-controller: notification template jinja whitelist byp… | LOW | 2.7 | 2.7 | — | redhat | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-96545 |
Gimp: gimp: out-of-bounds heap read in the 4bpp tim image loader | MEDIUM | 4.4 | 4.4 | — | redhat | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-76089 |
Formie: Missing authorization on sent notification resend modal exposes submission PII | HIGH | 7.7 | 7.7 | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-82356 |
Imprivata EAM: Unrotatable X.509 RSA Key Pair in Production | — | — | — | — | certcc | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-71462 |
Automation-controller: automation-controller-container: automation-controller: custom_venv_path setting provides filesys… | MEDIUM | 4.1 | 4.1 | — | redhat | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-71461 |
Automation-controller: automation-controller-container: automation-controller: verbose internal exception … | MEDIUM | 4.3 | 4.3 | — | redhat | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-71460 |
Automation-controller: automation-controller-container: automation-controller: any authenticated user reads red hat subs… | MEDIUM | 4.3 | 4.3 | — | redhat | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-76648 |
Automation-controller: automation-controller-container: aap controller: copyapiview.post() missing read … | HIGH | 8.5 | 8.5 | — | redhat | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-92692 |
Sulu: JCR-SQL2 injection via `categories` query parameter (unauthenticated) | MEDIUM | 6.9 | — | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-77423 |
JLine: ReDoS in Built-in Less Viewer Search | HIGH | 7.5 | 7.5 | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-95604 |
WordPress Loops & Logic plugin <= 4.2.4 - Broken Access Control vulnerability | HIGH | 7.5 | 7.5 | — | Patchstack | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-95603 |
WordPress Reycob Product Import Export plugin <= 2.3.0 - PHP Object Injection vulnerability | HIGH | 7.2 | 7.2 | — | Patchstack | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-95602 |
WordPress YITH WooCommerce Request A Quote plugin < 4.46.1 - Insecure Direct Object References (IDOR) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-95601 |
WordPress Product Filter by WBW plugin <= 3.1.7 - SQL Injection vulnerability | CRITICAL | 9.3 | 9.3 | — | Patchstack | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |