s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVEs

Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.

Reset

230056 CVEs matched. Showing 2551–2600 (page 52 of 4602).

HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.

Click a column header to sort all results; click the active column again to reverse.

CVE-ID ↕ Title ↕ Severity ↕ Score (overview) ↕ NVD Score MSRC Score CNA ↕ Published ↕ Remediations Threat Source
CVE-2026-63278 Package URLs can be used to exfiltrate arbitrary INI file values and environment variables MEDIUM 6.7 — — Document Fdn. 2026-09-22 10 — raw · ⬇
CVE-2026-63276 Stack buffer overflow in CFF to Type 1 font conversion MEDIUM 5.4 — — Document Fdn. 2026-09-22 10 — raw · ⬇
CVE-2026-63275 Stack buffer overflow in CFF font hint handling MEDIUM 5.4 — — Document Fdn. 2026-09-22 10 — raw · ⬇
CVE-2026-63274 Heap buffer overflow in PDF import stream handling MEDIUM 5.4 — — Document Fdn. 2026-09-22 10 — raw · ⬇
CVE-2026-63273 Heap buffer overflow in PDF import encryption handling MEDIUM 5.4 — — Document Fdn. 2026-09-22 10 — raw · ⬇
CVE-2026-63272 Heap buffer overflow in WMF text record import MEDIUM 5.4 — — Document Fdn. 2026-09-22 10 — raw · ⬇
CVE-2026-95623 Tauri framework v2 SSRF Protection Bypass via HTTP Redirects MEDIUM 5.6 5.6 — JFROG 2026-09-22 10 — raw · ⬇
CVE-2026-90990 Livestatus injection via monitoring filter values MEDIUM 5.3 — — Checkmk 2026-09-22 10 — raw · ⬇
CVE-2026-92882 Redact SNMP community, SNMPv3 pass phrases, and IPMI password in host config REST API GET responses LOW 2.3 — — Checkmk 2026-09-22 10 — raw · ⬇
CVE-2026-25265 Creation of Temporary File with Insecure Permissions in Qualcomm Software Center HIGH 8.8 8.8 — qualcomm 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-25264 Uncontrolled Search Path Element in Qualcomm Software Center HIGH 8.8 8.8 — qualcomm 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-25262 Write-what-where Condition in Primary Bootloader MEDIUM 6.9 6.9 — qualcomm 2026-09-22 10 — raw · ⬇
CVE-2026-25255 Exposed function in Qualcomm Package Manager and Qualcomm Software Center. HIGH 8.8 8.8 — qualcomm 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-25254 Improper authorization in Qualcomm Software Center CRITICAL 9.8 9.8 — qualcomm 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-90882 Reflected arbitrary origins with credentials, allowing cross-origin reads of authenticated user data HIGH 8.7 — — eclipse 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-94117 WordPress HashBar – WordPress Notification Bar plugin <= 2.0.3 - SQL Injection vulnerability HIGH 7.6 7.6 — Patchstack 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-93556 Direct references to unsafe objects (IDOR) in Tankuam Places by Kompini CRITICAL 9.3 — — INCIBE 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-65634 Superlinear CPU denial of service in Erlang/OTP ASN.1 OBJECT IDENTIFIER decoder HIGH 8.2 — — EEF 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-68956 SSH daemon allocates unbounded idle session channels, bypassing max_channels HIGH 7.1 — — EEF 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-89422 TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension CRITICAL 9.3 — — EEF 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-93928 WordPress Taxi Booking Manager for WooCommerce plugin < 2.0.8 - Broken Authentication vulnerability HIGH 7.3 7.3 — Patchstack 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-95508 Libslirp: libslirp: heap buffer overflow in dhcpv6/tftp response builders on small interface mtu HIGH 7.4 7.4 7.0 redhat 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-95511 CVE-2026-95511 — — — — redhat 2026-09-22 10 — raw · ⬇
CVE-2026-15095 Product Feed Manager for WooCommerce <= 6.6.43 - Authenticated (Shop Manager+) Path Traversal to File Deletion via 'prov… MEDIUM 4.9 4.9 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2026-9231 WP Travel Engine <= 6.8.0 - Authenticated (Contributor+) Local File Inclusion via 'template' Shortcode Attribute HIGH 7.5 7.5 — Wordfence 2026-09-22 1 ⚠ Threat raw · ⬇
CVE-2026-95503 Keycloak-services: keycloak-services: potential kdc spoofing bypass when kerberos password authentication is enabled MEDIUM 6.8 6.8 — redhat 2026-09-22 10 — raw · ⬇
CVE-2026-93836 WPC Product Bundles for WooCommerce <= 8.6.6 - Unauthenticated Stored Cross-Site Scripting via 'qty' Parameter HIGH 7.2 7.2 — Wordfence 2026-09-22 1 ⚠ Threat raw · ⬇
CVE-2026-9004 WP-CRM System <= 3.4.6 - Authenticated (Contributor+) Exposure of Sensitive Information via 'contact_id' Parameter MEDIUM 4.3 4.3 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2026-7622 ThumbPress <= 6.2.1 - Missing Authorization to Authenticated (Subscriber+) Plugin Deactivation MEDIUM 4.3 4.3 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2026-18345 WP User Manager <= 2.9.18 - Missing Authorization to Authenticated (Subscriber+) Stripe Account Hijack via Stripe Connec… MEDIUM 4.3 4.3 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2025-1280 BM Content Builder < 3.17.1 - Authenticated (Subscriber+) Arbitrary File Read MEDIUM 6.5 6.5 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2025-14487 Handily <= 1.0.3 - Missing Authorization to Unauthenticated Arbitrary Stripe Payment Settings Modification via 'stripe_p… MEDIUM 5.3 5.3 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2026-93778 WP Yelp Review Slider <= 9.2 - Unauthenticated Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_dow… HIGH 7.2 7.2 — Wordfence 2026-09-22 1 ⚠ Threat raw · ⬇
CVE-2026-92235 WP Ultimate Review <= 2.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_submit_review_data[xs_re… HIGH 8.1 8.1 — Wordfence 2026-09-22 1 ⚠ Threat raw · ⬇
CVE-2026-91092 wpForo Forum <= 3.1.5 - Missing Authorization to Authenticated (Subscriber+) Guest Post Takeover via wpforo_post_edit Ac… MEDIUM 4.3 4.3 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2026-6922 WP Table Builder <= 2.2.1 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'ids' Par… HIGH 7.1 7.1 — Wordfence 2026-09-22 2 ⚠ Threat raw · ⬇
CVE-2026-1645 Hostel <= 1.1.8 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'custom_currency' Parameter and Localiz… MEDIUM 4.4 4.4 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2026-18439 Tutor LMS <= 4.0.7 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Quiz Question/Answer Modifica… MEDIUM 4.3 4.3 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2025-1281 BM Content Builder < 3.17.1 - Authenticated (Subscriber+) Arbitrary File Deletion HIGH 8.8 8.8 — Wordfence 2026-09-22 1 ⚠ Threat raw · ⬇
CVE-2026-4123 RW Elephant Rental Inventory <= 2.3.13 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via… MEDIUM 4.3 4.3 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2025-14484 Image Buzz <= 1.0.3 - Missing Authorization to Unauthenticated Arbitrary API Key Modification via 'pixabay_api' Paramete… MEDIUM 5.3 5.3 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2025-14486 PixelPlay <= 1.0.2 - Missing Authorization to Unauthenticated Arbitrary API Key Deletion via 'clear_api_type' Parameter MEDIUM 5.3 5.3 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2026-92969 HUSKY <= 1.4.4 - Unauthenticated Local File Inclusion via 'custom_tpl' Shortcode Attribute via 'woof_draw_products' AJAX HIGH 8.1 8.1 — Wordfence 2026-09-22 1 ⚠ Threat raw · ⬇
CVE-2026-16778 Live Composer <= 2.1.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'dslc_module_downloads_output' Sh… MEDIUM 6.4 6.4 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2026-12995 Custom Field Template <= 2.7.8 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Media File D… MEDIUM 4.3 4.3 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2026-93952 Security Advisory 0183 CRITICAL 9.5 10.0 — Arista 2026-09-22 1 ⚠ Threat raw · ⬇
CVE-2026-87082 Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in… — — 7.5 — CPANSec 2026-09-22 20 ⚠ Threat raw · ⬇
CVE-2026-87081 Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label… — — 7.5 — CPANSec 2026-09-22 20 ⚠ Threat raw · ⬇
CVE-2026-87080 Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never… — — 9.1 — CPANSec 2026-09-22 20 ⚠ Threat raw · ⬇
CVE-2026-87079 Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long… — — 7.5 — CPANSec 2026-09-22 20 ⚠ Threat raw · ⬇