s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVEs

Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.

Reset

230056 CVEs matched. Showing 2401–2450 (page 49 of 4602).

HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.

Click a column header to sort all results; click the active column again to reverse.

CVE-ID ↕ Title ↕ Severity ↕ Score (overview) ↕ NVD Score MSRC Score CNA ↕ Published ↕ Remediations Threat Source
CVE-2026-77258 MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path() HIGH 7.7 7.7 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-77274 MCP Atlassian: SSRF Protection Bypass HIGH 8.8 — — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-95624 Tauri framework v2 malicious downgrade via allow_downgrades from frontend code MEDIUM 6.8 6.8 — JFROG 2026-09-22 10 — raw · ⬇
CVE-2026-95656 dgtlmoon changedetection.io Preview Endpoint __init__.py add_watch_ui_snapshot server-side request forgery MEDIUM 6.9 7.3 — VulDB 2026-09-22 10 — raw · ⬇
CVE-2026-85995 Notepad++: Authenticode verification bypass allows modified updater execution HIGH 7.3 7.3 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-86056 Notepad++: Null pointer dereference in NPPM_SAVESESSION message handler causes crash (DoS) MEDIUM 5.5 5.5 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-77605 Notepad++ “Run by system” executes *.txt.cmd when user selected *.txt (target confusion → command execution) HIGH 7.8 7.8 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-86054 Notepad++: Stack Buffer Overflow in `NppParameters::writeSession` via overlong session path HIGH 7.8 7.8 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-85288 Notepad++: Shortcuts.xml macro HMAC bypass still reachable via the "Run a Macro Multiple Times" dialog MEDIUM 6.7 6.7 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-85279 Notepad++: Stack Buffer Overflow in Plugin Lexer Loading via Unchecked GetLexerCount() Return Value HIGH 8.6 8.6 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-93345 MikroTik RouterOS < 7.25beta4 Improper Input Validation DoS via BGP Labelled-VPN NLRI HIGH 8.7 7.5 — VulnCheck 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-94384 Missing Authorization in sfExecuteAWSService Lambda Dispatcher in Amazon Connect Salesforce Lambda MEDIUM 6.4 8.1 — AMZN 2026-09-22 10 — raw · ⬇
CVE-2026-83597 Netdata: Local Privilege Escalation in Netdata Windows Agent installer via MSI Repair Execution HIGH 7.0 7.0 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-83600 Netdata: Streaming protocol chart slot guard off-by-one allows ~16 GiB allocation request, crashing parent agent MEDIUM 6.5 6.5 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-83598 Netdata: Local Privilege Escalation in Netdata Agent Windows installer via PowerShell Profile Hijack in MSI Repair HIGH 7.8 7.8 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-83603 Netdata: Local Root via ndsudo Arbitrary socket_path → fail2ban-client Pickle RCE HIGH 8.4 8.4 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-83601 Netdata: Streaming protocol dimension slot has no upper-bound guard, allowing integer overflow and out-of-bounds write MEDIUM 6.5 6.5 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-83602 Netdata: Unauthenticated remote PUT to /api/v3/settings bypasses IP allowlist controls via HTTP_ACL_NOCHECK MEDIUM 6.5 6.5 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-83599 Netdata: WebSocket Decompression Bomb HIGH 7.5 7.5 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-13087 Kernel: heap out-of-bounds write in the linux kernel rpc-over-rdma server reply path... HIGH 8.8 8.8 — redhat 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-84301 FastGPT safe axios SSRF guard still allows DNS rebinding TOCTOU on protected outbound requests MEDIUM 6.3 6.3 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-95818 AT_SECURE program buffer overflow via $ORIGIN processing LOW 3.6 3.6 3.6 glibc 2026-09-22 10 — raw · ⬇
CVE-2026-76805 Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode MEDIUM 5.3 5.3 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-76802 Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass MEDIUM 4.7 4.7 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-87902 CVE-2026-87902 — — 8.1 — hackerone 2026-09-22 12 ⚠ Threat raw · ⬇
CVE-2026-76819 CVE-2026-76819 — — — — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-76804 Nuclei: Local File Read via Workflow File-Protocol Gate Bypass MEDIUM 5.5 5.5 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-76803 Nuclei: Local File Read via MySQL Client Sandbox Bypass MEDIUM 5.3 5.3 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-83803 Sentry: Unsafe pickle deserialization in Relocation Feature HIGH 7.7 — — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-86062 LightRAG: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content MEDIUM 6.1 6.1 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-85740 LightRAG: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download g… HIGH 7.1 7.1 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-85734 LightRAG: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks CRITICAL 9.1 9.1 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-94455 Unauthenticated /enterprise/create-user mints lifetime top-tier organizations and discloses their API key HIGH 7.1 7.1 — postiz 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-85725 LightRAG: Plaintext Passwords Compared Without Constant-Time Function MEDIUM 5.9 5.9 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-85709 LightRAG: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses MEDIUM 5.3 5.3 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-86059 Dokploy: Git Provider Credential Exposure via Unprotected .one Endpoints and application.one CRITICAL 9.6 9.6 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-94456 Unauthenticated recovery of the Math.random() state behind OAuth tokens, authorization codes, client secrets and organiz… CRITICAL 9.1 9.1 — postiz 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-56682 9Router: Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header MEDIUM 5.3 5.3 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-56681 9Router: Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header HIGH 7.3 7.3 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-86805 AT_SECURE programs may load attacker-controlled code via $ORIGIN MEDIUM 6.3 6.3 6.3 glibc 2026-09-22 10 — raw · ⬇
CVE-2026-86698 Refresh tokens accepted as private repository credentials at the CDN LOW 2.3 — — EEF 2026-09-22 10 — raw · ⬇
CVE-2026-75517 Novu: Cross-Environment Integration Manipulation (IDOR) MEDIUM 6.5 6.5 — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-90462 Sssd: sssd: fail-open in ldap ppolicy access check allows continued authorization MEDIUM 5.4 5.4 — redhat 2026-09-22 10 — raw · ⬇
CVE-2026-75511 Novu: Server-Side Request Forgery (SSRF) via Chat Provider Webhook URLs MEDIUM 5.3 — — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-75510 Novu: Stored XSS in In-App Inbox via notification redirect.url javascript: scheme MEDIUM 5.1 — — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-94640 Rpcbind: unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of service HIGH 7.5 7.5 — redhat 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-70410 Apache Calcite Avatica: Unrestricted class initialization when instantiating plugins — — 8.8 — apache 2026-09-22 20 ⚠ Threat raw · ⬇
CVE-2026-88010 Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle MEDIUM 6.3 — — GitHub_M 2026-09-22 10 — raw · ⬇
CVE-2026-75608 Frigate: Viewer-Role User Can Access go2rtc Internal API to obtain sensitive information HIGH 7.7 7.7 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-75607 Frigate: WebSocket Missing Authorization — Viewer Can Execute Admin-Only Operations HIGH 8.1 8.1 — GitHub_M 2026-09-22 10 ⚠ Threat raw · ⬇