s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVEs

Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.

Reset

204905 CVEs matched. Showing 201–250 (page 5 of 4099).

HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.

Click a column header to sort all results; click the active column again to reverse.

CVE-ID Title Severity Score (overview) NVD Score MSRC Score CNA Published Remediations Threat Source
CVE-2026-14804 Hardcoded Cryptographic Key in Bilin Software's HUMANIST Digital Human Resources CRITICAL 9.1 TR-CERT 2026-08-04 ⚠ Threat raw ·
CVE-2026-14219 URL Redirection in Bilin Software's HUMANIST Digital Human Resources MEDIUM 5.4 TR-CERT 2026-08-04 raw ·
CVE-2026-14194 Path Traversal Allows Arbitrary File Download in Bilin Software's HUMANIST Digital Human Resources MEDIUM 6.5 TR-CERT 2026-08-04 raw ·
CVE-2026-14175 Unrestricted File Upload in Bilin Software's HUMANIST Digital Human Resources CRITICAL 9.8 TR-CERT 2026-08-04 ⚠ Threat raw ·
CVE-2026-18772 CVE-2026-18772 MEDIUM 5.5 samsung.tv_appliance 2026-08-04 raw ·
CVE-2026-15721 Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HUMANIST Digital Human Resources CRITICAL 9.8 TR-CERT 2026-08-04 ⚠ Threat raw ·
CVE-2026-18759 An improper authentication and path traversal vulnerability exists in ASUSTOR Backup Plan and ASUSTOR EZ Sync. HIGH 8.5 ASUSTOR1 2026-08-04 ⚠ Threat raw ·
CVE-2026-18755 GV-ASManager DLL hijacking vulnerability HIGH 7.3 GV 2026-08-04 ⚠ Threat raw ·
CVE-2026-18754 Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-Cloud) CRITICAL 9.1 GV 2026-08-04 ⚠ Threat raw ·
CVE-2026-18753 Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-ASManager) CRITICAL 9.1 GV 2026-08-04 ⚠ Threat raw ·
CVE-2026-67243 CVE-2026-67243 HIGH 8.6 jpcert 2026-08-04 ⚠ Threat raw ·
CVE-2026-64565 Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() Linux 2026-08-04 raw ·
CVE-2026-64564 sctp: don't free the ASCONF's own transport in DEL-IP processing Linux 2026-08-04 raw ·
CVE-2026-64563 rhashtable: clear stale iter->p on table restart Linux 2026-08-04 raw ·
CVE-2026-64562 KVM: nVMX: Hide shadow VMCS right after VMCLEAR Linux 2026-08-04 raw ·
CVE-2026-64561 KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Linux 2026-08-04 raw ·
CVE-2026-16548 Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint WPScan 2026-08-04 raw ·
CVE-2026-16547 REST API Log < 1.7.1 - Unauthenticated Sensitive Log Data Disclosure via Download Endpoint WPScan 2026-08-04 raw ·
CVE-2026-16546 Wired Impact Volunteer Management < 2.8.2 - Subscriber+ Arbitrary RSVP Removal via wivm_remove_rsvp WPScan 2026-08-04 raw ·
CVE-2026-16296 Clearfy < 2.4.3 - Open Redirect via Cyrlitera 404 Handler WPScan 2026-08-04 raw ·
CVE-2026-16295 Clearfy < 2.4.3 - Subscriber+ Sensitive Information Disclosure via Factory Page-Action Dispatcher WPScan 2026-08-04 raw ·
CVE-2026-16293 Blubrry PowerPress < 11.16.11 - Contributor+ Stored XSS via Podcast Episode Chapters URL WPScan 2026-08-04 raw ·
CVE-2026-16070 Brizy - Page Builder < 2.8.19 - Contributor+ Template Type Update via IDOR WPScan 2026-08-04 raw ·
CVE-2026-16069 Brizy - Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal Point WPScan 2026-08-04 raw ·
CVE-2026-16068 Brizy - Page Builder < 2.8.19 - Author+ Stored XSS via brizy_set_project Global Project Code Asset WPScan 2026-08-04 raw ·
CVE-2026-16056 Contest Gallery < 30.0.7 - Subscriber+ OpenAI Prompt History Disclosure via post_cg_get_openai_prompts WPScan 2026-08-04 raw ·
CVE-2026-16035 miniOrange 2FA < 6.2.7 - Subscriber+ Arbitrary-Recipient OTP Send WPScan 2026-08-04 raw ·
CVE-2026-15958 Easy Dropbox Integration < 2.2.0 - Unauthenticated Arbitrary Connected Dropbox File Access and Upload via nopriv AJAX WPScan 2026-08-04 raw ·
CVE-2026-15233 Nested Pages < 3.2.15 - Editor+ Stored XSS via Post Title WPScan 2026-08-04 raw ·
CVE-2026-14939 Visualizer: Tables and Charts Manager < 4.0.6 - Contributor+ Server-Side Request Forgery via JSON Import WPScan 2026-08-04 raw ·
CVE-2026-14872 Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 - Authenticated SQL Injection via id Parameter WPScan 2026-08-04 raw ·
CVE-2026-14848 Paid Member Subscriptions < 3.0.8 - Subscriber+ Cross-User Subscription Hijack via process_checkout WPScan 2026-08-04 raw ·
CVE-2026-14824 Quiz And Survey Master < 11.2.2 - Contributor+ Stored XSS via Polar Question WPScan 2026-08-04 raw ·
CVE-2026-14816 The GDPR Framework < 2.4.0 - Unauthenticated Consent Record Forgery and Do Not Sell Requests Spam WPScan 2026-08-04 raw ·
CVE-2026-12698 wpForo Forum < 3.1.3 - Subscriber+ Account Status and Reputation Manipulation via Profile Update Mass Assignment WPScan 2026-08-04 raw ·
CVE-2026-11366 MonsterInsights < 11.1.0 - Unauthenticated Measurement Protocol Secret Update via Empty-Key HMAC Bypass WPScan 2026-08-04 raw ·
CVE-2026-10526 EmbedPress < 4.6.1 - Unauthenticated Blind SSRF WPScan 2026-08-04 raw ·
CVE-2026-16536 Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_id WPScan 2026-08-04 raw ·
CVE-2026-16623 Create Block Theme < 2.10.0 - Admin+ PHP Code Injection via Pattern Save (Multisite) WPScan 2026-08-04 raw ·
CVE-2026-16618 ImproveSEO <= 2.0.11 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution WPScan 2026-08-04 raw ·
CVE-2026-18739 Popt-devel: popt-static: off-by-one in poptstuffargs LOW 2.5 redhat 2026-08-04 raw ·
CVE-2026-68744 Sssd: sssd: nss responder uninitialized heap disclosure in initgroups reply LOW 3.3 redhat 2026-08-04 raw ·
CVE-2026-18569 Keycloak-services: keycloak-services: oidc backchannel logout accepts unsigned forged logout tokens LOW 3.7 redhat 2026-08-04 raw ·
CVE-2026-16881 CVE-2026-16881 HIGH 8.7 LY-Corporation 2026-08-04 ⚠ Threat raw ·
CVE-2026-42169 Gimp: gimp apng loader heap-buffer-overflow when fctl width exceeds ihdr width (file-png.c) HIGH 7.3 redhat 2026-08-04 ⚠ Threat raw ·
CVE-2026-18723 diaowen DWSurvey Survey Status up-survey-status.do improper authorization MEDIUM 5.3 VulDB 2026-08-04 raw ·
CVE-2026-18722 diaowen DWSurvey dev-survey.do in DwDeisgnSurveyController.devSurvey. authorization MEDIUM 5.3 VulDB 2026-08-04 raw ·
CVE-2026-18721 kalcaddle kodbox SSO API Login apiLogin redirect MEDIUM 5.3 VulDB 2026-08-04 raw ·
CVE-2026-14818 CVE-2026-14818 HIGH 7.2 Zyxel 2026-08-04 ⚠ Threat raw ·
CVE-2026-17614 Wildfly-core: path traversal on wildfly domain controller MEDIUM 4.4 redhat 2026-08-04 raw ·