CVEs
Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.
229687 CVEs matched. Showing 1451–1500 (page 30 of 4594).
HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.
Click a column header to sort all results; click the active column again to reverse.
| CVE-ID ↕ | Title ↕ | Severity ↕ | Score (overview) ↕ | NVD Score | MSRC Score | CNA ↕ | Published ↕ | Remediations | Threat | Source |
|---|---|---|---|---|---|---|---|---|---|---|
CVE-2026-77601 |
OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting | HIGH | 8.8 | 8.8 | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96872 |
WikiLambda public function execution bypasses the unsaved-code permission through nested Z825 compositions | LOW | 2.9 | — | — | wikimedia-foundation | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-84499 |
Automation-controller: automation-controller-container: automation-controller: write-only survey password recovered in p… | HIGH | 7.7 | 7.7 | — | redhat | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-84502 |
Automation-controller: automation-controller-container: automation-controller: project scm_url argument injection into `… | CRITICAL | 9.9 | 9.9 | — | redhat | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-61695 |
Wire Swift runtime: negative LENGTH_DELIMITED length in skipGroup() crashes any protobuf-decoding service | HIGH | 7.5 | 7.5 | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-90903 |
Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Stor… | HIGH | 7.2 | — | — | Joomla | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-90901 |
Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extens… | HIGH | 8.6 | — | — | Joomla | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-90905 |
Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension… | HIGH | 7.2 | — | — | Joomla | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-84474 |
Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege esc… | CRITICAL | 9.9 | 9.9 | — | redhat | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-59990 |
Jawn: Uncontrolled nesting depth in JSON parser | HIGH | 7.5 | 7.5 | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-82368 |
CVE-2026-82368 | HIGH | 8.7 | — | — | brocade | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-90902 |
Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extensio… | HIGH | 8.2 | — | — | Joomla | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-61814 |
Jawn: Quadratic parsing effort in AsyncParser | HIGH | 7.5 | 7.5 | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-90904 |
Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store ext… | HIGH | 8.6 | — | — | Joomla | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-90899 |
Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.… | HIGH | 8.2 | — | — | Joomla | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-84486 |
Automation-controller: automation-controller-container: automation-controller: unauthenticated debug scheduler-trigger e… | HIGH | 8.2 | 8.2 | — | redhat | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-76087 |
Formie: Unauthenticated users can overwrite incomplete submissions via submit action | HIGH | 8.2 | 8.2 | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-90900 |
Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Stor… | MEDIUM | 5.3 | — | — | Joomla | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-76086 |
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials | HIGH | 8.5 | 8.5 | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96548 |
sfturing hosp_order jdbc.properties hard-coded credentials | MEDIUM | 6.3 | 5.6 | — | VulDB | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-96546 |
Gimp: gimp: one-byte out-of-bounds heap read in the uncompressed dds loader | LOW | 2.5 | 2.5 | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-71465 |
Automation-controller: automation-controller-container: automation-controller: ad-hoc command limit field allows cli arg… | LOW | 3.1 | 3.1 | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-71464 |
Automation-controller: automation-controller-container: automation-controller: schedule and workflowjobtemplatenode scm_… | LOW | 3.1 | 3.1 | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-71463 |
Automation-controller: automation-controller-container: automation-controller: notification template jinja whitelist byp… | LOW | 2.7 | 2.7 | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-96545 |
Gimp: gimp: out-of-bounds heap read in the 4bpp tim image loader | MEDIUM | 4.4 | 4.4 | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-76089 |
Formie: Missing authorization on sent notification resend modal exposes submission PII | HIGH | 7.7 | 7.7 | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-82356 |
Imprivata EAM: Unrotatable X.509 RSA Key Pair in Production | — | — | — | — | certcc | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-71462 |
Automation-controller: automation-controller-container: automation-controller: custom_venv_path setting provides filesys… | MEDIUM | 4.1 | 4.1 | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-71461 |
Automation-controller: automation-controller-container: automation-controller: verbose internal exception … | MEDIUM | 4.3 | 4.3 | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-71460 |
Automation-controller: automation-controller-container: automation-controller: any authenticated user reads red hat subs… | MEDIUM | 4.3 | 4.3 | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-76648 |
Automation-controller: automation-controller-container: aap controller: copyapiview.post() missing read … | HIGH | 8.5 | 8.5 | — | redhat | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-92692 |
Sulu: JCR-SQL2 injection via `categories` query parameter (unauthenticated) | MEDIUM | 6.9 | — | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-77423 |
JLine: ReDoS in Built-in Less Viewer Search | HIGH | 7.5 | 7.5 | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95604 |
WordPress Loops & Logic plugin <= 4.2.4 - Broken Access Control vulnerability | HIGH | 7.5 | 7.5 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95603 |
WordPress Reycob Product Import Export plugin <= 2.3.0 - PHP Object Injection vulnerability | HIGH | 7.2 | 7.2 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95602 |
WordPress YITH WooCommerce Request A Quote plugin < 4.46.1 - Insecure Direct Object References (IDOR) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-95601 |
WordPress Product Filter by WBW plugin <= 3.1.7 - SQL Injection vulnerability | CRITICAL | 9.3 | 9.3 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95600 |
WordPress TrustedLogin Connector plugin <= 2.0.3 - Sensitive Data Exposure vulnerability | MEDIUM | 5.3 | 5.3 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-95593 |
WordPress Ultimeter plugin <= 3.0.8 - SQL Injection vulnerability | HIGH | 7.6 | 7.6 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95592 |
WordPress Team plugin <= 6.0.0 - Insecure Direct Object References (IDOR) vulnerability | MEDIUM | 5.3 | 5.3 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-95590 |
WordPress Tainacan plugin <= 1.2.0 - SQL Injection vulnerability | HIGH | 7.1 | 7.1 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95586 |
WordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.50 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-95530 |
WordPress PixelYourSite – Your smart PIXEL (TAG) Manager plugin <= 11.4.1 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-95529 |
WordPress Calculated Fields Form plugin <= 5.5.1.1 - Cross Site Scripting (XSS) vulnerability | HIGH | 7.1 | 7.1 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95528 |
WordPress Core Web Vitals & PageSpeed Booster plugin <= 1.0.31 - Cross Site Scripting (XSS) vulnerability | HIGH | 7.1 | 7.1 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95527 |
WordPress Conekta Payment Gateway plugin <= 6.2.4 - Broken Access Control vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-95525 |
WordPress WP User Frontend plugin <= 4.3.11 - Arbitrary File Deletion vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-95524 |
WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability | MEDIUM | 5.3 | 5.3 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-95523 |
WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-95522 |
WordPress Easy Digital Downloads plugin <= 3.7.0 - SQL Injection vulnerability | HIGH | 7.6 | 7.6 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |