s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVEs

Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.

Reset

229687 CVEs matched. Showing 1451–1500 (page 30 of 4594).

HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.

Click a column header to sort all results; click the active column again to reverse.

CVE-ID ↕ Title ↕ Severity ↕ Score (overview) ↕ NVD Score MSRC Score CNA ↕ Published ↕ Remediations Threat Source
CVE-2026-77601 OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting HIGH 8.8 8.8 — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-96872 WikiLambda public function execution bypasses the unsaved-code permission through nested Z825 compositions LOW 2.9 — — wikimedia-foundation 2026-09-23 10 — raw · ⬇
CVE-2026-84499 Automation-controller: automation-controller-container: automation-controller: write-only survey password recovered in p… HIGH 7.7 7.7 — redhat 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-84502 Automation-controller: automation-controller-container: automation-controller: project scm_url argument injection into `… CRITICAL 9.9 9.9 — redhat 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-61695 Wire Swift runtime: negative LENGTH_DELIMITED length in skipGroup() crashes any protobuf-decoding service HIGH 7.5 7.5 — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-90903 Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Stor… HIGH 7.2 — — Joomla 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-90901 Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extens… HIGH 8.6 — — Joomla 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-90905 Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension… HIGH 7.2 — — Joomla 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-84474 Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege esc… CRITICAL 9.9 9.9 — redhat 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-59990 Jawn: Uncontrolled nesting depth in JSON parser HIGH 7.5 7.5 — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-82368 CVE-2026-82368 HIGH 8.7 — — brocade 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-90902 Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extensio… HIGH 8.2 — — Joomla 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-61814 Jawn: Quadratic parsing effort in AsyncParser HIGH 7.5 7.5 — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-90904 Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store ext… HIGH 8.6 — — Joomla 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-90899 Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.… HIGH 8.2 — — Joomla 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-84486 Automation-controller: automation-controller-container: automation-controller: unauthenticated debug scheduler-trigger e… HIGH 8.2 8.2 — redhat 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-76087 Formie: Unauthenticated users can overwrite incomplete submissions via submit action HIGH 8.2 8.2 — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-90900 Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Stor… MEDIUM 5.3 — — Joomla 2026-09-23 10 — raw · ⬇
CVE-2026-76086 Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials HIGH 8.5 8.5 — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-96548 sfturing hosp_order jdbc.properties hard-coded credentials MEDIUM 6.3 5.6 — VulDB 2026-09-23 10 — raw · ⬇
CVE-2026-96546 Gimp: gimp: one-byte out-of-bounds heap read in the uncompressed dds loader LOW 2.5 2.5 — redhat 2026-09-23 10 — raw · ⬇
CVE-2026-71465 Automation-controller: automation-controller-container: automation-controller: ad-hoc command limit field allows cli arg… LOW 3.1 3.1 — redhat 2026-09-23 10 — raw · ⬇
CVE-2026-71464 Automation-controller: automation-controller-container: automation-controller: schedule and workflowjobtemplatenode scm_… LOW 3.1 3.1 — redhat 2026-09-23 10 — raw · ⬇
CVE-2026-71463 Automation-controller: automation-controller-container: automation-controller: notification template jinja whitelist byp… LOW 2.7 2.7 — redhat 2026-09-23 10 — raw · ⬇
CVE-2026-96545 Gimp: gimp: out-of-bounds heap read in the 4bpp tim image loader MEDIUM 4.4 4.4 — redhat 2026-09-23 10 — raw · ⬇
CVE-2026-76089 Formie: Missing authorization on sent notification resend modal exposes submission PII HIGH 7.7 7.7 — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-82356 Imprivata EAM: Unrotatable X.509 RSA Key Pair in Production — — — — certcc 2026-09-23 10 — raw · ⬇
CVE-2026-71462 Automation-controller: automation-controller-container: automation-controller: custom_venv_path setting provides filesys… MEDIUM 4.1 4.1 — redhat 2026-09-23 10 — raw · ⬇
CVE-2026-71461 Automation-controller: automation-controller-container: automation-controller: verbose internal exception … MEDIUM 4.3 4.3 — redhat 2026-09-23 10 — raw · ⬇
CVE-2026-71460 Automation-controller: automation-controller-container: automation-controller: any authenticated user reads red hat subs… MEDIUM 4.3 4.3 — redhat 2026-09-23 10 — raw · ⬇
CVE-2026-76648 Automation-controller: automation-controller-container: aap controller: copyapiview.post() missing read … HIGH 8.5 8.5 — redhat 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-92692 Sulu: JCR-SQL2 injection via `categories` query parameter (unauthenticated) MEDIUM 6.9 — — GitHub_M 2026-09-23 10 — raw · ⬇
CVE-2026-77423 JLine: ReDoS in Built-in Less Viewer Search HIGH 7.5 7.5 — GitHub_M 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-95604 WordPress Loops & Logic plugin <= 4.2.4 - Broken Access Control vulnerability HIGH 7.5 7.5 — Patchstack 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-95603 WordPress Reycob Product Import Export plugin <= 2.3.0 - PHP Object Injection vulnerability HIGH 7.2 7.2 — Patchstack 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-95602 WordPress YITH WooCommerce Request A Quote plugin < 4.46.1 - Insecure Direct Object References (IDOR) vulnerability MEDIUM 6.5 6.5 — Patchstack 2026-09-23 10 — raw · ⬇
CVE-2026-95601 WordPress Product Filter by WBW plugin <= 3.1.7 - SQL Injection vulnerability CRITICAL 9.3 9.3 — Patchstack 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-95600 WordPress TrustedLogin Connector plugin <= 2.0.3 - Sensitive Data Exposure vulnerability MEDIUM 5.3 5.3 — Patchstack 2026-09-23 10 — raw · ⬇
CVE-2026-95593 WordPress Ultimeter plugin <= 3.0.8 - SQL Injection vulnerability HIGH 7.6 7.6 — Patchstack 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-95592 WordPress Team plugin <= 6.0.0 - Insecure Direct Object References (IDOR) vulnerability MEDIUM 5.3 5.3 — Patchstack 2026-09-23 10 — raw · ⬇
CVE-2026-95590 WordPress Tainacan plugin <= 1.2.0 - SQL Injection vulnerability HIGH 7.1 7.1 — Patchstack 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-95586 WordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.50 - Cross Site Scripting (XSS) vulnerability MEDIUM 6.5 6.5 — Patchstack 2026-09-23 10 — raw · ⬇
CVE-2026-95530 WordPress PixelYourSite – Your smart PIXEL (TAG) Manager plugin <= 11.4.1 - Cross Site Scripting (XSS) vulnerability MEDIUM 6.5 6.5 — Patchstack 2026-09-23 10 — raw · ⬇
CVE-2026-95529 WordPress Calculated Fields Form plugin <= 5.5.1.1 - Cross Site Scripting (XSS) vulnerability HIGH 7.1 7.1 — Patchstack 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-95528 WordPress Core Web Vitals & PageSpeed Booster plugin <= 1.0.31 - Cross Site Scripting (XSS) vulnerability HIGH 7.1 7.1 — Patchstack 2026-09-23 10 ⚠ Threat raw · ⬇
CVE-2026-95527 WordPress Conekta Payment Gateway plugin <= 6.2.4 - Broken Access Control vulnerability MEDIUM 6.5 6.5 — Patchstack 2026-09-23 10 — raw · ⬇
CVE-2026-95525 WordPress WP User Frontend plugin <= 4.3.11 - Arbitrary File Deletion vulnerability MEDIUM 6.5 6.5 — Patchstack 2026-09-23 10 — raw · ⬇
CVE-2026-95524 WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability MEDIUM 5.3 5.3 — Patchstack 2026-09-23 10 — raw · ⬇
CVE-2026-95523 WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability MEDIUM 6.5 6.5 — Patchstack 2026-09-23 10 — raw · ⬇
CVE-2026-95522 WordPress Easy Digital Downloads plugin <= 3.7.0 - SQL Injection vulnerability HIGH 7.6 7.6 — Patchstack 2026-09-23 10 ⚠ Threat raw · ⬇