CVEs
Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.
229687 CVEs matched. Showing 1701–1750 (page 35 of 4594).
HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.
Click a column header to sort all results; click the active column again to reverse.
| CVE-ID ↕ | Title ↕ | Severity ↕ | Score (overview) ↕ | NVD Score | MSRC Score | CNA ↕ | Published ↕ | Remediations | Threat | Source |
|---|---|---|---|---|---|---|---|---|---|---|
CVE-2026-91999 |
Apache Sling XSS: Improper escaping in the XSS Webconsole plugin | — | — | 6.1 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-92001 |
Apache Sling XSS: Missing parser resource limits | — | — | 6.1 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-73192 |
Apache Sling XSS: XSS possible through XSSAPI.getValidHref() | — | — | 6.1 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-31377 |
Apache Doris: Improper Authentication Allows Unauthorized Access to FE Meta Service | HIGH | 7.5 | 7.5 | — | apache | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-42801 |
Deference after null check in as_rrc | HIGH | 7.4 | 7.4 | — | ASR | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95625 |
Tauri framework v2 missing updater signature version number validation can be exploited into forced downgrade | MEDIUM | 5.9 | 5.9 | — | JFROG | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-93368 |
Rename wp-login.php to anything you want <= 2.0.1 - Unauthenticated SQL Injection via 'log' (Username) Parameter | HIGH | 7.5 | 7.5 | — | Wordfence | 2026-09-23 | 1 | ⚠ Threat | raw · ⬇ |
CVE-2026-15027 |
Changing|CGServiSign - OS Command Injection | HIGH | 8.6 | 8.8 | — | twcert | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91788 |
Foxit PDF Editor/Reader Missing Authorization Information Disclosure Vulnerability | MEDIUM | 4.7 | 4.7 | — | Foxit | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-91790 |
Foxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91791 |
Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91792 |
Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91793 |
Foxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91794 |
Foxit PDF Editor/Reader DeviceN Colorspace Out-Of-Bounds Write Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91795 |
Foxit PDF Editor/Reader FileOpen Uninitialized Variable Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91796 |
Foxit PDF Editor/Reader importIcon NTLM Response Information Disclosure Vulnerability | MEDIUM | 6.1 | 6.1 | — | Foxit | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-91797 |
Foxit PDF Editor/Reader Portfolio Directory Traversal Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91799 |
Foxit Editor/Reader Array resetForm Use-After-Free Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91805 |
Use-after-free Vulnerability in Foxit PDF Editor/Reader Page-tree Handling | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91800 |
Foxit PDF Editor installer local privilege escalation | HIGH | 8.8 | 8.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91801 |
Foxit PDF Editor/Reader RichMedia Annotation Directory Traversal Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91802 |
Foxit PDF Editor/Reader — Heap Buffer Overflow in WebP Image Decoding via Bitmap Stride Confusion | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91804 |
Foxit PDF Editor/Reader Out-of-bounds Write Vulnerability While Rendering | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91806 |
Foxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91807 |
Foxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability | MEDIUM | 6.1 | 6.1 | — | Foxit | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-91798 |
Foxit PDF Editor/Reader Updater Privilege Escalation | HIGH | 8.8 | 8.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91803 |
Security Vulnerability Report – Foxit PDF Editor/Reader Updater DLL Search Path Hijacking | HIGH | 8.8 | 8.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91808 |
Foxit PDF Editor/Reader JPEG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability | MEDIUM | 6.1 | 6.1 | — | Foxit | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-91810 |
Foxit PDF Editor/Reader Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability | MEDIUM | 6.1 | 6.1 | — | Foxit | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-91811 |
Foxit PDF Editor/Reader PRC Stream Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91812 |
Foxit PDF Editor/Reader FoxitUpdater Improper Certificate Validation Local Privilege Escalation Vulnerability | HIGH | 7.9 | 7.9 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91813 |
Foxit PDF Editor/Reader FoxitUpdater Race Condition Local Privilege Escalation Vulnerability | HIGH | 8.8 | 8.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91815 |
Foxit PDF Editor/Reader JPEG2000 Parsing Memory Corruption Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91814 |
Security vulnerability: Foxit PDF Editor/Reader Fails to Detect Modifications to Signed Documents Displaying Newly Added… | MEDIUM | 5.3 | 5.3 | — | Foxit | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-91816 |
Foxit PDF Editor/Reader AcroForm Use-After-Free Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91817 |
Foxit PDF Editor/Reader AcroForm Out-of-Bounds Read Remote Code Execution Vulnerability | MEDIUM | 6.1 | 6.1 | — | Foxit | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-91818 |
Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91789 |
Foxit PDF Editor/Reader U3D File Parsing Integer Overflow Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91809 |
Foxit PDF Editor/Reader Annotation Use-After-Free Information Disclosure Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-92378 |
uniFLOW Online Legacy UI Previous login session retained when entering Reduced Function Login | MEDIUM | 4.1 | — | — | Canon_EMEA | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-50228 |
Electron DevTools Arbitrary Code Execution Vulnerability in NitroSense | MEDIUM | 6.1 | — | — | Acer | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-50227 |
MQTT WebSocket Command Execution Vulnerability in NitroSense | MEDIUM | 6.1 | — | — | Acer | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-70125 |
Microsoft Office Outlook Remote Code Execution Vulnerability | HIGH | 8.8 | 8.8 | 8.8 | microsoft | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-82331 |
Apache BuildStream: tar source extraction escape | — | — | 9.8 | — | apache | 2026-09-23 | 20 | ⚠ Threat | raw · ⬇ |
CVE-2026-6831 |
Advanced Contact form 7 DB <= 2.1.1 - Missing Authorization to Authenticated (Contributor+) Information Disclosure via '… | MEDIUM | 6.5 | 6.5 | — | Wordfence | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-5924 |
Getwid <= 2.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Google Maps 'customStyle' | MEDIUM | 6.4 | 6.4 | — | Wordfence | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-93528 |
NP Quote Request for WooCommerce < 2.4.16 - Unauthenticated Order Data Disclosure via Quote Request Page | — | — | 3.7 | — | WPScan | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-93511 |
Premium Packages < 7.2.1 - Unauthenticated PayPal Webhook Signature Verification Bypass | — | — | 5.3 | — | WPScan | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-93510 |
Points and Rewards for WooCommerce < 2.10.4 - Subscriber+ Arbitrary Points and Wallet Balance Manipulation via assign_cl… | — | — | 4.3 | — | WPScan | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-93508 |
WC Fields Factory < 4.1.11 - Subscriber+ Arbitrary Post Meta Manipulation via AJAX | — | — | 8.1 | — | WPScan | 2026-09-23 | 20 | ⚠ Threat | raw · ⬇ |