CVEs
Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.
229687 CVEs matched. Showing 1601–1650 (page 33 of 4594).
HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.
Click a column header to sort all results; click the active column again to reverse.
| CVE-ID ↕ | Title ↕ | Severity ↕ | Score (overview) ↕ | NVD Score | MSRC Score | CNA ↕ | Published ↕ | Remediations | Threat | Source |
|---|---|---|---|---|---|---|---|---|---|---|
CVE-2026-18490 |
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities | HIGH | 8.8 | 8.8 | — | ibm | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-18185 |
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities | HIGH | 7.3 | 7.3 | — | ibm | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-18184 |
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities | HIGH | 7.4 | 7.4 | — | ibm | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-18181 |
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities | HIGH | 8.1 | 8.1 | — | ibm | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-18180 |
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities | MEDIUM | 6.5 | 6.5 | — | ibm | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-96675 |
alsa-lib through 1.2.16.1 Denial of Service via pcm_multi | MEDIUM | 4.8 | 3.3 | — | VulnCheck | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-96674 |
alsa-lib through 1.2.16.1 Integer Overflow via Topology File | MEDIUM | 4.8 | 4.4 | — | VulnCheck | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-96673 |
Photoview through 2.4.0 SQL Injection via album download route | HIGH | 8.7 | 7.5 | — | VulnCheck | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96672 |
Frappe ERPNext before 16.34.1 Unauthorized Method Invocation | MEDIUM | 5.3 | 6.4 | — | VulnCheck | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-96276 |
Flatpak: flatpak: arbitrary write in host context via flatpak build-init | — | — | 9.8 | — | redhat | 2026-09-23 | 20 | ⚠ Threat | raw · ⬇ |
CVE-2026-96275 |
Flatpak: flatpak: arbitrary write access as root via extra-data extraction | HIGH | 8.8 | 8.8 | — | redhat | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96600 |
Isotope eCommerce through 2.9.10 SQL Injection via Backend Callbacks | HIGH | 7.0 | 5.5 | — | VulnCheck | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96599 |
Isotope eCommerce through 2.9.10 Weak Order Identifier Generation | HIGH | 8.2 | 5.9 | — | VulnCheck | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-92419 |
IDOR in WEBCON BPS | MEDIUM | 5.3 | — | — | CERT-PL | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-55610 |
InvoiceShelf has cross-company user read/update IDOR that enables cross-tenant account takeover | HIGH | 8.7 | 8.7 | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-73591 |
CVE-2026-73591 | HIGH | 7.5 | 7.5 | — | dell | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-92164 |
Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local files | MEDIUM | 6.5 | 6.5 | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-73589 |
CVE-2026-73589 | MEDIUM | 6.3 | 6.3 | — | dell | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-73858 |
Solspace Freeform: Limited Twig template injection via submitted field values | MEDIUM | 5.3 | 5.3 | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-73588 |
CVE-2026-73588 | HIGH | 7.4 | 7.4 | — | dell | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-73587 |
CVE-2026-73587 | MEDIUM | 6.8 | 6.8 | — | dell | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-96611 |
CVE-2026-96611 | MEDIUM | 6.9 | 6.9 | — | mitre | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-88974 |
WPGraphQL: Contributor can publish and modify posts without the required capabilities via updatePost | MEDIUM | 5.4 | — | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-73586 |
CVE-2026-73586 | MEDIUM | 6.4 | 6.4 | — | dell | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-63000 |
REDAXO: Missing CSRF Protection on Package Update Action Allows Forced Addon Updates | MEDIUM | 6.4 | 6.4 | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-96609 |
CVE-2026-96609 | HIGH | 7.1 | — | — | mitre | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-62998 |
REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration | MEDIUM | 4.3 | 4.3 | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-63002 |
REDAXO: Stored XSS in Mediapool Sync Page via Unescaped Filesystem Filenames | MEDIUM | 4.8 | 4.8 | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-71178 |
CVE-2026-71178 | LOW | 3.7 | 3.7 | — | dell | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-63001 |
REDAXO: Stored XSS via Unescaped Media Manager Type Name in `mediaIsInUse()` | MEDIUM | 4.8 | 4.8 | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-71177 |
CVE-2026-71177 | MEDIUM | 5.4 | 5.4 | — | dell | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-61834 |
scim-patch: Mutation of Inherited Built-in Method Objects | MEDIUM | 4.3 | 4.3 | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-61413 |
CVE-2026-61413 | MEDIUM | 6.8 | 6.8 | — | dell | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-18179 |
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities | MEDIUM | 6.5 | 6.5 | — | ibm | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-59167 |
SunEditor: Critical XSS vulnerability - sanitizer bypass | CRITICAL | 10.0 | 10.0 | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-18177 |
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities | HIGH | 7.1 | 7.1 | — | ibm | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-86678 |
Broken Authentication vulnerability | HIGH | 8.8 | 8.8 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-86677 |
Broken Authentication vulnerability | HIGH | 8.8 | 8.8 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96560 |
LightLLM through 1.2.0 Unauthenticated Remote Code Execution via NCCL PD RPyC Control Channel | CRITICAL | 9.3 | 9.8 | — | VulnCheck | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-86679 |
Broken Access Control vulnerability | HIGH | 7.1 | 7.1 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-12974 |
Security Policy Bypass in Forcepoint Security Engine (NGFW) | HIGH | 7.9 | — | — | forcepoint | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-86683 |
Broken Authentication Vulnerability | HIGH | 8.1 | 8.1 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96512 |
Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authorization | HIGH | 7.8 | 7.8 | — | redhat | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-86681 |
Broken Access Control vulnerability | HIGH | 7.6 | 7.6 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-86708 |
Sensitive data exposure | CRITICAL | 10.0 | 10.0 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95676 |
AuthPoint Gateway Improper Authentication in LDAP Sync Allows First-Factor Authentication Bypass | HIGH | 7.4 | — | — | WatchGuard | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-19599 |
Remote Code Execution vulnerability | CRITICAL | 9.9 | 9.9 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-75825 |
Authentication Bypass vulnerability | HIGH | 8.8 | 8.8 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-86247 |
Apache Tomcat Native: Client certificate requirements can be down-graded | — | — | 7.4 | — | apache | 2026-09-23 | 20 | ⚠ Threat | raw · ⬇ |
CVE-2026-76978 |
Command Injection vulnerability | HIGH | 8.8 | 8.8 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |