s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVEs

Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.

Reset

229688 CVEs matched. Showing 2451–2500 (page 50 of 4594).

HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.

Click a column header to sort all results; click the active column again to reverse.

CVE-ID ↕ Title ↕ Severity ↕ Score (overview) ↕ NVD Score MSRC Score CNA ↕ Published ↕ Remediations Threat Source
CVE-2026-80110 Pki-core: dogtag pki v2 rest acl filter's reverse-lexicographic tie-break lets a ca agent invoke the admin-only raw prof… HIGH 8.1 8.1 — redhat 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-75939 Openshift/oc-mirror: release signature verification: openpgp signatureerror checked before signed body is consumed HIGH 7.4 7.4 — redhat 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-94404 MISP CSRF vulnerability allows unauthorized attribute modification HIGH 7.1 — — CIRCL 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-88807 libXrender RenderQueryPictFormats Reply Heap-based Buffer Overflow HIGH 8.9 — — suse 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-94387 Aureus ERP before 1.6.0 Stored XSS via Chatter Field-Change Log MEDIUM 5.1 5.4 — VulnCheck 2026-09-21 10 — raw · ⬇
CVE-2025-71421 UVdesk core-framework before 1.1.7 Privilege Escalation via editAgent HIGH 8.6 7.2 — VulnCheck 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2025-71420 UVdesk core-framework before 1.1.7 Authorization Bypass via Saved Reply MEDIUM 5.3 4.3 — VulnCheck 2026-09-21 10 — raw · ⬇
CVE-2025-71419 UVdesk core-framework before 1.1.7 Stored XSS via SwiftMailer MEDIUM 5.1 5.4 — VulnCheck 2026-09-21 10 — raw · ⬇
CVE-2026-88806 libX11 XkbGetMap Reply Heap-based Buffer Overflow HIGH 7.5 7.5 7.5 suse 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-94401 MISP Arbitrary Local File Read and SSRF via MISP Export Upload HIGH 8.3 — — CIRCL 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-94394 MISP ObjectReferencesController: Granular Distribution and Sharing Group Restrictions Bypassed When Adding Object Refere… MEDIUM 6.3 — — CIRCL 2026-09-21 10 — raw · ⬇
CVE-2026-94393 MISP Event Report Cross-Event Reparenting via Unscoped UUID Resolution in editReport MEDIUM 6.4 — — CIRCL 2026-09-21 10 — raw · ⬇
CVE-2026-85220 Denial-of-Service in the Thinkst Canary Redis service LOW 3.7 3.7 — ThinkstAppliedResearch 2026-09-21 10 — raw · ⬇
CVE-2026-94382 Beszel before 0.19.0 Insecure Direct Object Reference via user-alerts LOW 2.3 4.2 — VulnCheck 2026-09-21 10 — raw · ⬇
CVE-2026-94383 MISP Blocklist Workflow Module: Arbitrary Script Execution via Unrestricted File Extension HIGH 8.6 — — CIRCL 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-94216 ST Engineering iDirect Evolution/Velocity WebServer Evolution HTTP Header webserver authorize redirect MEDIUM 5.3 4.3 — VulDB 2026-09-21 10 — raw · ⬇
CVE-2026-94381 MISP Privilege Escalation: Read-Only API Key User Can Regain Full Role via updateLoginTime HIGH 8.7 — — CIRCL 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-94379 MISP: HTTP Method Bypass of Login Security Controls (Bruteforce Protection and Email OTP) MEDIUM 6.9 — — CIRCL 2026-09-21 10 — raw · ⬇
CVE-2026-94374 MISP: IDOR via Client-Supplied Report ID in Module Results Processing Allows Reparenting and Overwriting of Other Events… HIGH 8.3 — — CIRCL 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-94373 MISP DOM-based Cross-Site Scripting via innerHTML in Contextual Menu MEDIUM 6.3 — — CIRCL 2026-09-21 10 — raw · ⬇
CVE-2026-94214 ST Engineering iDirect Evolution/Velocity WebServer Evolution Management Service login.html redirect MEDIUM 5.3 4.3 — VulDB 2026-09-21 10 — raw · ⬇
CVE-2026-84285 OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 HIGH 8.8 8.8 — 3DS 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-94372 Stored Cross-Site Scripting via Unescaped Galaxy Cluster Tag Names in MISP Default Theme Galaxies Index MEDIUM 6.3 — — CIRCL 2026-09-21 10 — raw · ⬇
CVE-2026-94211 Hyve5 Leantime Project Dashboard show.blade.php cross site scripting MEDIUM 4.8 2.4 — VulDB 2026-09-21 10 — raw · ⬇
CVE-2026-94368 Noobaa-core: noobaa-core: presigned put url escalation to copyobject via unsigned x-amz-copy-source header HIGH 7.1 7.1 — redhat 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-89139 Temporal Server worker deployment compute provider executes a caller-supplied command on the Worker Service host HIGH 8.7 — — Temporal 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-87858 Temporal Server completion callback source header can direct attacker-chosen requests to the internal frontend with admi… HIGH 7.2 — — Temporal 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-65654 temporalio/ringpop-go fails to enforce configured label limits on inbound membership gossip HIGH 8.7 — — Temporal 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-65653 temporalio/tchannel-go zero-chunk call fragment causes process termination HIGH 8.7 — — Temporal 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-65652 temporalio/tchannel-go malformed checksum type causes process termination HIGH 8.7 — — Temporal 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-65651 temporalio/sqlparser deeply nested unary expressions can cause a fatal stack overflow during AST traversal HIGH 8.7 — — Temporal 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-16651 temporalio/sqlparser malformed MySQL version comments can cause a panic HIGH 8.7 — — Temporal 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-94210 Hyve5 Leantime Kanban Board Tickets.php getAllGrouped cross site scripting MEDIUM 5.1 3.5 — VulDB 2026-09-21 10 — raw · ⬇
CVE-2026-91867 Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitely — — 4.3 — apache 2026-09-21 10 — raw · ⬇
CVE-2026-91866 Apache Neethi: Crafted policies cause unbounded work during intersection leading to denial of service — — 7.5 — apache 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-91865 Apache Neethi: Crafted policy references cause exponential expansion during normalization leading to denial of service — — 7.5 — apache 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-91864 Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustion — — 7.5 — apache 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-91863 Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows denial of service — — 7.5 — apache 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-16652 Temporal Server Schedule exclusion search can cause excessive CPU consumption HIGH 7.1 — — Temporal 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-77021 Missing decompression size limit in agent receiver allows memory exhaustion via push agent data MEDIUM 5.3 — — Checkmk 2026-09-21 10 — raw · ⬇
CVE-2026-92612 CVE-2026-92612 LOW 1.0 — — eclipse 2026-09-21 10 — raw · ⬇
CVE-2026-92574 Cri-o: cri-o checkpoint restore bypasses destination security context HIGH 8.8 8.8 — redhat 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-91921 Cross-Site Scripting (XSS) in 1millionbot’s AI chatbot platform MEDIUM 5.1 — — INCIBE 2026-09-21 10 — raw · ⬇
CVE-2026-94277 Stored Cross-Site Scripting in MISP Galaxy Matrix Statistics via Unescaped Galaxy Name MEDIUM 6.3 — — CIRCL 2026-09-21 10 — raw · ⬇
CVE-2025-12999 CVE-2025-12999 CRITICAL 9.1 — — eclipse 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-92400 Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via Sandbox IPN Environment Confusion MEDIUM 5.3 5.3 — WPScan 2026-09-21 10 — raw · ⬇
CVE-2026-86802 To Do List Member 1.4 - 1.6 - Unauthenticated Content Injection via Import LOW 3.7 3.7 — WPScan 2026-09-21 10 — raw · ⬇
CVE-2026-85113 GiveWP < 4.16.9 - Unauthenticated Arbitrary Shortcode Execution via Donor Name MEDIUM 6.5 6.5 — WPScan 2026-09-21 10 — raw · ⬇
CVE-2026-85010 RestroPress < 3.4.6 - Unauthenticated Price Manipulation via Cart Add-ons MEDIUM 5.3 5.3 — WPScan 2026-09-21 10 — raw · ⬇
CVE-2026-94152 Omega Solution FBP Fulfillment by People User Profile API user authorization MEDIUM 5.3 4.3 — VulDB 2026-09-21 10 — raw · ⬇