s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVEs

Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.

Reset

204905 CVEs matched. Showing 151–200 (page 4 of 4099).

HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.

Click a column header to sort all results; click the active column again to reverse.

CVE-ID Title Severity Score (overview) NVD Score MSRC Score CNA Published Remediations Threat Source
CVE-2026-24079 Missing Authentication for Critical Function in Data Modem HIGH 8.1 qualcomm 2026-08-04 ⚠ Threat raw ·
CVE-2026-24078 Exposure of Private Personal Information to an Unauthorized Actor in Data Modem MEDIUM 6.5 qualcomm 2026-08-04 raw ·
CVE-2026-24077 Integer Underflow (Wrap or Wraparound) in WLAN Host MEDIUM 6.5 qualcomm 2026-08-04 raw ·
CVE-2026-24076 Buffer Copy Without Checking Size of Input in Bluetooth HOST MEDIUM 6.7 qualcomm 2026-08-04 raw ·
CVE-2026-21366 Integer Overflow or Wraparound in Data Network Stack & Connectivity HIGH 7.8 qualcomm 2026-08-04 ⚠ Threat raw ·
CVE-2026-18773 NousResearch hermes-agent Quick run.py _check_slash_access authorization MEDIUM 5.3 VulDB 2026-08-04 raw ·
CVE-2026-69252 Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspa… HIGH 7.2 GitHub_M 2026-08-04 ⚠ Threat raw ·
CVE-2026-18801 Stored Clickhouse SQL Injection Through Customer Usage Attribution CRITICAL 9.3 Kong 2026-08-04 ⚠ Threat raw ·
CVE-2026-18770 vibesurf-ai VibeSurf Python Validation code code injection MEDIUM 6.9 VulDB 2026-08-04 raw ·
CVE-2026-68494 jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for CVE-2026-18401 / GH… HIGH 8.7 HeroDevs 2026-08-04 ⚠ Threat raw ·
CVE-2026-67618 marimo < 0.23.15 API Key Exfiltration via Malicious Notebook PEP-723 Metadata HIGH 7.1 VulnCheck 2026-08-04 ⚠ Threat raw ·
CVE-2026-69251 Flowise RCE via TypeORM DataSource CRITICAL 9.0 GitHub_M 2026-08-04 ⚠ Threat raw ·
CVE-2026-11368 Use-after-free in Bluetooth host ATT TX completion on disconnect mid-transfer HIGH 7.1 zephyr 2026-08-04 ⚠ Threat raw ·
CVE-2026-18401 jackson-core: Number length constraint bypass in non-blocking (async) JSON parser leads to potential denial of service MEDIUM 6.9 HeroDevs 2026-08-04 raw ·
CVE-2026-69250 Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration HIGH 8.5 GitHub_M 2026-08-04 ⚠ Threat raw ·
CVE-2026-18766 chetans9 core-php-admin-panel customers.php sql injection MEDIUM 5.3 VulDB 2026-08-04 raw ·
CVE-2026-67200 Perspective 5.0.0 Path Traversal via cwd_static_file_handler HIGH 8.7 VulnCheck 2026-08-04 ⚠ Threat raw ·
CVE-2026-67199 Perspective 5.0.0 DoS via Loop Expression Evaluation HIGH 7.1 VulnCheck 2026-08-04 ⚠ Threat raw ·
CVE-2026-67198 Perspective 5.0.0 DoS via VirtualServer Protocol Dispatcher HIGH 8.7 VulnCheck 2026-08-04 ⚠ Threat raw ·
CVE-2026-67196 Perspective 5.0.0 XSS via Debug Plugin innerHTML Interpolation MEDIUM 5.1 VulnCheck 2026-08-04 raw ·
CVE-2026-67195 Perspective 5.0.0 RCE via eval() Expression Injection HIGH 8.7 VulnCheck 2026-08-04 ⚠ Threat raw ·
CVE-2026-18650 Missing Authorization Leading to Root Code Execution in HAVELSAN's Liman MYS HIGH 8.8 TR-CERT 2026-08-04 ⚠ Threat raw ·
CVE-2026-61514 Puwell IP Camera 2.x - 4.x Unauthenticated Access via TCP Port 23456 CRITICAL 9.3 VulnCheck 2026-08-04 ⚠ Threat raw ·
CVE-2026-61515 Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell CRITICAL 9.3 VulnCheck 2026-08-04 ⚠ Threat raw ·
CVE-2026-70368 Stunnel: stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message MEDIUM 6.5 redhat 2026-08-04 raw ·
CVE-2026-70367 Stunnel: ssrf bypass in stunnel socks proxy via ipv4-mapped ipv6 loopback and unspecified addresses allows access to loo… MEDIUM 5.4 redhat 2026-08-04 raw ·
CVE-2026-14337 Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a use… MEDIUM 4.6 Pega 2026-08-04 raw ·
CVE-2026-17070 Vault Credential Confusion via Authorization Bypass in HAVELSAN's Liman MYS HIGH 8.8 TR-CERT 2026-08-04 ⚠ Threat raw ·
CVE-2026-70373 Koha: SQL Injection in reports/issues_stats.pl TuranSec 2026-08-04 raw ·
CVE-2026-70372 Koha: SQL Injection in reports/bor_issues_top.pl TuranSec 2026-08-04 raw ·
CVE-2026-70371 Koha: SQL Injection in reports/issues_avg_stats.pl TuranSec 2026-08-04 raw ·
CVE-2026-70370 Koha: SQL Injection in reports/catalogue_stats.pl TuranSec 2026-08-04 raw ·
CVE-2026-70369 Koha: SQL Injection in reports/acquisitions_stats.pl TuranSec 2026-08-04 raw ·
CVE-2026-10710 FBX ExtractDrive Stack-Based Buffer Overflow Vulnerability in Autodesk FBX SDK HIGH 7.8 autodesk 2026-08-04 ⚠ Threat raw ·
CVE-2026-10709 FBX BinaryReadSectionHeader Stack-Based Buffer Overflow Vulnerability in Autodesk FBX SDK HIGH 7.8 autodesk 2026-08-04 ⚠ Threat raw ·
CVE-2026-18806 Arbitrary Block Device Write via Missing Validation in TÜBİTAK BİLGEM's pardus-image-writer HIGH 7.1 TR-CERT 2026-08-04 ⚠ Threat raw ·
CVE-2026-18809 Information disclosure in Firefox for Android and Firefox Focus for Android mozilla 2026-08-04 raw ·
CVE-2026-63248 CVE-2026-63248 MEDIUM 6.9 eclipse 2026-08-04 raw ·
CVE-2026-58080 CVE-2026-58080 HIGH 8.8 eclipse 2026-08-04 ⚠ Threat raw ·
CVE-2026-63252 CVE-2026-63252 HIGH 8.7 eclipse 2026-08-04 ⚠ Threat raw ·
CVE-2026-62927 CVE-2026-62927 HIGH 8.7 eclipse 2026-08-04 ⚠ Threat raw ·
CVE-2026-60007 CVE-2026-60007 CRITICAL 9.1 eclipse 2026-08-04 ⚠ Threat raw ·
CVE-2026-61387 CVE-2026-61387 MEDIUM 6.9 eclipse 2026-08-04 raw ·
CVE-2026-66883 Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup MEDIUM 6.3 EEF 2026-08-04 raw ·
CVE-2026-66884 Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF prote… LOW 2.1 EEF 2026-08-04 raw ·
CVE-2026-10050 Digest authentication lossy encoding HIGH 8.7 eclipse 2026-08-04 ⚠ Threat raw ·
CVE-2026-14202 Username Enumeration via Differential Login Responses in Bilin Software's HUMANIST Digital Human Resources MEDIUM 5.3 TR-CERT 2026-08-04 raw ·
CVE-2026-14465 Session Fixation in Bilin Software's HUMANIST Digital Human Resources MEDIUM 6.5 TR-CERT 2026-08-04 raw ·
CVE-2026-14192 Stored XSS in Bilin Software's HUMANIST Digital Human Resources MEDIUM 5.4 TR-CERT 2026-08-04 raw ·
CVE-2026-14838 Session Token Exposure in URL Leading to Account Takeover in Bilin Software's HUMANIST Digital Human Resources HIGH 7.4 TR-CERT 2026-08-04 ⚠ Threat raw ·