s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVEs

Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.

Reset

229687 CVEs matched. Showing 2151–2200 (page 44 of 4594).

HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.

Click a column header to sort all results; click the active column again to reverse.

CVE-ID ↕ Title ↕ Severity ↕ Score (overview) ↕ NVD Score MSRC Score CNA ↕ Published ↕ Remediations Threat Source
CVE-2026-24239 CVE-2026-24239 HIGH 7.8 7.8 — nvidia 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-24267 CVE-2026-24267 HIGH 7.8 7.8 — nvidia 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-93344 MarketKing < 2.1.72 Missing Authorization via marketking_get_page_content AJAX HIGH 7.1 6.5 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-93343 MarketKing < 2.1.72 Missing Authorization via marketking_admin_vendors_ajax HIGH 7.1 6.5 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-95682 MISP Stored Cross-Site Scripting via Unescaped Organization Name in Admin Email View MEDIUM 4.8 — — CIRCL 2026-09-22 10 — raw · ⬇
CVE-2026-93342 MarketKing < 2.1.72 Missing Authorization via marketking_duplicate_product AJAX MEDIUM 5.3 5.4 — VulnCheck 2026-09-22 10 — raw · ⬇
CVE-2026-12718 SQLi in Karel Electronics' KarelIPS CRITICAL 9.8 9.8 — TR-CERT 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-93341 MarketKing < 2.1.72 Missing Authorization via marketking_send_refund AJAX MEDIUM 5.3 4.3 — VulnCheck 2026-09-22 10 — raw · ⬇
CVE-2026-95679 MISP Unauthenticated Blind SSRF via XML Body Processing MEDIUM 6.9 — — CIRCL 2026-09-22 10 — raw · ⬇
CVE-2026-95675 D-Link DAP-1360 6.14 Unauthenticated RCE via Web Management Interface CRITICAL 9.3 9.8 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-95499 JosephChuks php-file-manager-with-code-editor filemanager.php move_uploaded_file unrestricted upload MEDIUM 6.9 7.3 — VulDB 2026-09-22 10 — raw · ⬇
CVE-2026-95674 MISP EventsController queryEnrichment allows querying unavailable or legacy modules without validation MEDIUM 5.3 — — CIRCL 2026-09-22 10 — raw · ⬇
CVE-2026-95671 MISP Collections: Missing Authorization Check for Sharing Group on PUT Request in collections/add MEDIUM 5.3 — — CIRCL 2026-09-22 10 — raw · ⬇
CVE-2026-95667 MISP Installer Log and FIFO Created World-Readable, Exposing Sensitive Credentials MEDIUM 6.9 — — CIRCL 2026-09-22 10 — raw · ⬇
CVE-2026-95666 Unbounded post ID array in the bulk reactions endpoint allows denial of service MEDIUM 4.3 4.3 — Mattermost 2026-09-22 10 — raw · ⬇
CVE-2026-95665 MISP Reflected Cross-Site Scripting in Event Export Confirmation Form via Unescaped JSON MEDIUM 5.1 — — CIRCL 2026-09-22 10 — raw · ⬇
CVE-2026-95396 sfturing hosp_order Public Search Handlers HospitalController.java cross site scripting MEDIUM 5.3 4.3 — VulDB 2026-09-22 10 — raw · ⬇
CVE-2026-93616 Directory Traversal and File upload allows execution of arbitrary script on the Management Server CRITICAL 9.8 9.8 — checkpoint 2026-09-22 1 ⚠ Threat raw · ⬇
CVE-2026-95661 MISP Reflected Cross-Site Scripting in Attribute Histogram via Unescaped URL-Supplied Type List MEDIUM 5.1 — — CIRCL 2026-09-22 10 — raw · ⬇
CVE-2026-95619 Gcc: libstdc++ integer overflow in `new` operator HIGH 7.7 7.7 — redhat 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-95659 MISP Reflected XSS via Unvalidated Object Type in AnalystData Overmind Thread MEDIUM 4.8 — — CIRCL 2026-09-22 10 — raw · ⬇
CVE-2026-95658 MISP CSRF vulnerability in workflow moduleStatelessExecution allows cross-site execution of workflow modules MEDIUM 6.9 — — CIRCL 2026-09-22 10 — raw · ⬇
CVE-2026-95273 dgtlmoon changedetection.io visual_selector_data flask_app.py static_content path traversal MEDIUM 5.3 4.3 — VulDB 2026-09-22 10 — raw · ⬇
CVE-2026-95272 dgtlmoon changedetection.io Screenshot flask_app.py static_content path traversal MEDIUM 6.3 3.7 — VulDB 2026-09-22 10 — raw · ⬇
CVE-2026-75791 Authentication bypass vulnerability HIGH 8.6 8.6 — Zohocorp 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-95271 dgtlmoon changedetection.io Authentication Hook flask_app.py check_authentication improper authentication MEDIUM 6.9 7.3 — VulDB 2026-09-22 10 — raw · ⬇
CVE-2026-74849 Remote code execution vulnerability CRITICAL 9.8 9.8 — Zohocorp 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-87119 mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credentia… HIGH 8.2 — — EEF 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-89420 Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free HIGH 7.1 — — EEF 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-95270 dgtlmoon changedetection.io Hash Comparison flask_app.py check_password timing discrepancy MEDIUM 6.3 3.7 — VulDB 2026-09-22 10 — raw · ⬇
CVE-2026-63279 Out of bounds read in PICT image import MEDIUM 5.4 — — Document Fdn. 2026-09-22 10 — raw · ⬇
CVE-2026-63278 Package URLs can be used to exfiltrate arbitrary INI file values and environment variables MEDIUM 6.7 — — Document Fdn. 2026-09-22 10 — raw · ⬇
CVE-2026-63276 Stack buffer overflow in CFF to Type 1 font conversion MEDIUM 5.4 — — Document Fdn. 2026-09-22 10 — raw · ⬇
CVE-2026-63275 Stack buffer overflow in CFF font hint handling MEDIUM 5.4 — — Document Fdn. 2026-09-22 10 — raw · ⬇
CVE-2026-63274 Heap buffer overflow in PDF import stream handling MEDIUM 5.4 — — Document Fdn. 2026-09-22 10 — raw · ⬇
CVE-2026-63273 Heap buffer overflow in PDF import encryption handling MEDIUM 5.4 — — Document Fdn. 2026-09-22 10 — raw · ⬇
CVE-2026-63272 Heap buffer overflow in WMF text record import MEDIUM 5.4 — — Document Fdn. 2026-09-22 10 — raw · ⬇
CVE-2026-95623 Tauri framework v2 SSRF Protection Bypass via HTTP Redirects MEDIUM 5.6 5.6 — JFROG 2026-09-22 10 — raw · ⬇
CVE-2026-90990 Livestatus injection via monitoring filter values MEDIUM 5.3 — — Checkmk 2026-09-22 10 — raw · ⬇
CVE-2026-92882 Redact SNMP community, SNMPv3 pass phrases, and IPMI password in host config REST API GET responses LOW 2.3 — — Checkmk 2026-09-22 10 — raw · ⬇
CVE-2026-25265 Creation of Temporary File with Insecure Permissions in Qualcomm Software Center HIGH 8.8 8.8 — qualcomm 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-25264 Uncontrolled Search Path Element in Qualcomm Software Center HIGH 8.8 8.8 — qualcomm 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-25262 Write-what-where Condition in Primary Bootloader MEDIUM 6.9 6.9 — qualcomm 2026-09-22 10 — raw · ⬇
CVE-2026-25255 Exposed function in Qualcomm Package Manager and Qualcomm Software Center. HIGH 8.8 8.8 — qualcomm 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-25254 Improper authorization in Qualcomm Software Center CRITICAL 9.8 9.8 — qualcomm 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-90882 Reflected arbitrary origins with credentials, allowing cross-origin reads of authenticated user data HIGH 8.7 — — eclipse 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-94117 WordPress HashBar – WordPress Notification Bar plugin <= 2.0.3 - SQL Injection vulnerability HIGH 7.6 7.6 — Patchstack 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-93556 Direct references to unsafe objects (IDOR) in Tankuam Places by Kompini CRITICAL 9.3 — — INCIBE 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-65634 Superlinear CPU denial of service in Erlang/OTP ASN.1 OBJECT IDENTIFIER decoder HIGH 8.2 — — EEF 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-68956 SSH daemon allocates unbounded idle session channels, bypassing max_channels HIGH 7.1 — — EEF 2026-09-22 10 ⚠ Threat raw · ⬇