s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVEs

Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.

Reset

229687 CVEs matched. Showing 2051–2100 (page 42 of 4594).

HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.

Click a column header to sort all results; click the active column again to reverse.

CVE-ID ↕ Title ↕ Severity ↕ Score (overview) ↕ NVD Score MSRC Score CNA ↕ Published ↕ Remediations Threat Source
CVE-2026-13087 Kernel: heap out-of-bounds write in the linux kernel rpc-over-rdma server reply path... HIGH 8.8 8.8 — redhat 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-84301 FastGPT safe axios SSRF guard still allows DNS rebinding TOCTOU on protected outbound requests MEDIUM 6.3 6.3 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-95818 AT_SECURE program buffer overflow via $ORIGIN processing LOW 3.6 3.6 3.6 glibc 2026-09-22 10 — raw · ⬇
CVE-2026-76805 Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode MEDIUM 5.3 5.3 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-76802 Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass MEDIUM 4.7 4.7 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-87902 CVE-2026-87902 — — 8.1 — hackerone 2026-09-22 12 ⚠ Threat raw · ⬇
CVE-2026-76819 CVE-2026-76819 — — — — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-76804 Nuclei: Local File Read via Workflow File-Protocol Gate Bypass MEDIUM 5.5 5.5 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-76803 Nuclei: Local File Read via MySQL Client Sandbox Bypass MEDIUM 5.3 5.3 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-83803 Sentry: Unsafe pickle deserialization in Relocation Feature HIGH 7.7 — — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-86062 LightRAG: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content MEDIUM 6.1 6.1 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-85740 LightRAG: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download g… HIGH 7.1 7.1 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-85734 LightRAG: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks CRITICAL 9.1 9.1 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-94455 Unauthenticated /enterprise/create-user mints lifetime top-tier organizations and discloses their API key HIGH 7.1 7.1 — postiz 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-85725 LightRAG: Plaintext Passwords Compared Without Constant-Time Function MEDIUM 5.9 5.9 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-85709 LightRAG: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses MEDIUM 5.3 5.3 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-86059 Dokploy: Git Provider Credential Exposure via Unprotected .one Endpoints and application.one CRITICAL 9.6 9.6 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-94456 Unauthenticated recovery of the Math.random() state behind OAuth tokens, authorization codes, client secrets and organiz… CRITICAL 9.1 9.1 — postiz 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-56682 9Router: Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header MEDIUM 5.3 5.3 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-56681 9Router: Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header HIGH 7.3 7.3 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-86805 AT_SECURE programs may load attacker-controlled code via $ORIGIN MEDIUM 6.3 6.3 6.3 glibc 2026-09-22 10 — raw · ⬇
CVE-2026-86698 Refresh tokens accepted as private repository credentials at the CDN LOW 2.3 — — EEF 2026-09-22 10 — raw · ⬇
CVE-2026-75517 Novu: Cross-Environment Integration Manipulation (IDOR) MEDIUM 6.5 6.5 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-90462 Sssd: sssd: fail-open in ldap ppolicy access check allows continued authorization MEDIUM 5.4 5.4 — redhat 2026-09-22 10 — raw · ⬇
CVE-2026-75511 Novu: Server-Side Request Forgery (SSRF) via Chat Provider Webhook URLs MEDIUM 5.3 — — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-75510 Novu: Stored XSS in In-App Inbox via notification redirect.url javascript: scheme MEDIUM 5.1 — — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-94640 Rpcbind: unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of service HIGH 7.5 7.5 — redhat 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-70410 Apache Calcite Avatica: Unrestricted class initialization when instantiating plugins — — 8.8 — apache 2026-09-22 20 ⚠ Threat raw · ⬇
CVE-2026-88010 Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle MEDIUM 6.3 — — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-75608 Frigate: Viewer-Role User Can Access go2rtc Internal API to obtain sensitive information HIGH 7.7 7.7 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-75607 Frigate: WebSocket Missing Authorization — Viewer Can Execute Admin-Only Operations HIGH 8.1 8.1 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-77637 Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope LOW 3.8 3.8 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-77633 Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service HIGH 7.1 7.1 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-79913 Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching i… MEDIUM 6.5 6.5 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-95655 Aureus ERP before 1.5.0 Unscoped Message Access via ChatterPanel HIGH 8.6 8.1 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-95654 Databasement before 1.7.14 Authorization Bypass via Stale Invitation Token CRITICAL 9.1 7.4 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-95653 Concrete CMS Community Store before 2.7.8 Predictable Digital Download Token HIGH 8.7 7.5 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-80156 Lantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload Filename Validation Bypass CRITICAL 9.4 9.1 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-63374 AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing CRITICAL 9.3 — — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-80155 Lantronix Autonomous Out-of-Band Devices Unauthenticated Authentication Bypass via snprintf Path Truncation CRITICAL 10.0 10.0 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-80154 Lantronix Autonomous Out-of-Band Devices Predictable Session Token with Validation Bypass HIGH 8.9 9.6 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-80152 Lantronix Autonomous Out-of-Band Devices OS Command Injection via set script schedule CRITICAL 9.4 9.1 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-92706 Dark Reader: Ability to request icon-like bitmap data from certain local web servers LOW 3.4 3.4 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-80151 Lantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs download CRITICAL 9.4 9.1 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-80150 Lantronix Autonomous Out-of-Band Devices WebTelnet SSRF via rooturl Parameter HIGH 7.7 7.5 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-80149 Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via rooturl Parameter HIGH 7.7 8.6 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-80148 Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via Username Truncation HIGH 7.7 8.6 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-85055 Twenty: Field-level read bypass HIGH 7.1 — — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-80147 Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom write CRITICAL 9.4 9.9 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-80146 Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom read CRITICAL 9.4 9.9 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇