CVEs
Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.
228318 CVEs matched. Showing 301–350 (page 7 of 4567).
HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.
Click a column header to sort all results; click the active column again to reverse.
| CVE-ID ↕ | Title ↕ | Severity ↕ | Score (overview) ↕ | NVD Score | MSRC Score | CNA ↕ | Published ↕ | Remediations | Threat | Source |
|---|---|---|---|---|---|---|---|---|---|---|
CVE-2026-86677 |
Broken Authentication vulnerability | HIGH | 8.8 | 8.8 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96560 |
LightLLM through 1.2.0 Unauthenticated Remote Code Execution via NCCL PD RPyC Control Channel | CRITICAL | 9.3 | 9.8 | — | VulnCheck | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-86679 |
Broken Access Control vulnerability | HIGH | 7.1 | 7.1 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-12974 |
Security Policy Bypass in Forcepoint Security Engine (NGFW) | HIGH | 7.9 | — | — | forcepoint | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-86683 |
Broken Authentication Vulnerability | HIGH | 8.1 | 8.1 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96512 |
Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authorization | HIGH | 7.8 | 7.8 | — | redhat | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-86681 |
Broken Access Control vulnerability | HIGH | 7.6 | 7.6 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-86708 |
Sensitive data exposure | CRITICAL | 10.0 | 10.0 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95676 |
AuthPoint Gateway Improper Authentication in LDAP Sync Allows First-Factor Authentication Bypass | HIGH | 7.4 | — | — | WatchGuard | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-19599 |
Remote Code Execution vulnerability | CRITICAL | 9.9 | 9.9 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-75825 |
Authentication Bypass vulnerability | HIGH | 8.8 | 8.8 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-86247 |
Apache Tomcat Native: Client certificate requirements can be down-graded | — | — | 7.4 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-76978 |
Command Injection vulnerability | HIGH | 8.8 | 8.8 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-86246 |
Apache Tomcat Native: Insecure OpenSSL options enabled | — | — | 9.1 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-86243 |
Apache Tomcat Native: DoS via TLS handshake | — | — | 7.5 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-76979 |
XML Injection vulnerability | HIGH | 7.7 | 7.7 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-84091 |
SUMIT Payment Gateway for WooCommerce < 4.0.0 - Unauthenticated Payment Confirmation Forgery via bit IPN | MEDIUM | 5.3 | 5.3 | — | WPScan | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-76980 |
Data Exposure vulnerability | HIGH | 7.4 | 7.4 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77112 |
SSRF Leading to JWT Token Disclosure in Global IT Informatics' Weoll | MEDIUM | 6.5 | 6.5 | — | TR-CERT | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-84787 |
Privilege Escalation vulnerability | HIGH | 8.1 | 8.1 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-84789 |
Broken Access Control vulnerability | HIGH | 7.1 | 7.1 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-84791 |
Broken Access Control vulnerability | HIGH | 7.1 | 7.1 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-80444 |
Unauthenticated Open Redirect Vulnerability in Abis Technology's AVESİS | MEDIUM | 5.4 | 5.4 | — | TR-CERT | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-78253 |
Denial-of-service (stack-exhaustion) vulnerability in QXmlStreamReader::readElementText() impacts Qt | LOW | 2.3 | — | — | Qt | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-15358 |
Path Traversal Vulnerability | HIGH | 7.5 | 7.5 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-87022 |
Apache Tomcat: WebSocket message smuggling with per-message-deflate | — | — | 7.5 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-86350 |
Apache Tomcat: Regression in fix for CVE-2026-41293 can trigger request header mix-up | — | — | 9.1 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-86248 |
Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is di… | — | — | 9.8 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-14913 |
SQL Injection vulnerability | HIGH | 8.8 | 8.8 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-79677 |
Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout | — | — | 7.5 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-78437 |
Apache Tomcat: HTTP/2 DoS via malformed request | — | — | 7.3 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-78383 |
Apache Tomcat: AJP DoS via missing request body | — | — | 7.5 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-77791 |
Apache Tomcat: DoS via busy wait during WebSocket close | — | — | 7.5 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-12370 |
Remote Code Execution Vulnerability | HIGH | 7.6 | 7.6 | — | Zohocorp | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-77762 |
Apache Tomcat: Stale HPACK emitter injects trailers into recycled pooled Request | — | — | 8.1 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-77756 |
Apache Tomcat: Transfer-Encoding honored for HTTP/1.0 requests | — | — | 3.7 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-76183 |
Apache Tomcat: Bypass of security constraints for WebSocket endpoints | — | — | 9.8 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-75973 |
Apache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configured | — | — | 7.3 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-96445 |
Keycloak-services: keycloak-services: conditional otp skip-header policy evaluated against untrusted proxy headers | MEDIUM | 6.8 | 6.8 | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-73581 |
Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore | — | — | 6.5 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-96446 |
Keycloak-services: keycloak-services: par single-use bypass via prompt=none silent authentication path | MEDIUM | 4.2 | 4.2 | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-5696 |
Multiple vulnerabilities in the Microweber administration panel | MEDIUM | 5.9 | — | — | INCIBE | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-5695 |
Multiple vulnerabilities in the Microweber administration panel | HIGH | 8.4 | — | — | INCIBE | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-90950 |
Paid Member Subscriptions < 3.1.0 - Unauthenticated reCAPTCHA Bypass via Registration Form | MEDIUM | 5.3 | 5.3 | — | WPScan | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-87978 |
Paymob for WooCommerce < 4.1.14 - Unauthenticated Payment Bypass via Unverified Subscription Transaction Callback | MEDIUM | 5.3 | 5.3 | — | WPScan | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-87848 |
MPCX Lightbox 1.2.2 - 1.2.5 - Unauthenticated Non-Public Post Content Disclosure | LOW | 3.7 | 3.7 | — | WPScan | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-87071 |
Forminator Forms < 1.57.2.1 - Unauthenticated Post Meta Injection on Submitted Posts | MEDIUM | 5.3 | 5.3 | — | WPScan | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-87070 |
Forminator Forms < 1.57.2.1 - Unauthenticated Poll Vote Limit Bypass via IP Spoofing | MEDIUM | 5.3 | 5.3 | — | WPScan | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-86612 |
Ninja Tables < 5.2.17 - Unauthenticated Arbitrary Shortcode Execution via Fluent Forms Data Source | MEDIUM | 5.6 | 5.6 | — | WPScan | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-86604 |
GTranslate < 5.0.1 - Unauthenticated Arbitrary Shortcode Execution via Email Translation | MEDIUM | 4.8 | 4.8 | — | WPScan | 2026-09-23 | 10 | — | raw · ⬇ |