s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVEs

Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.

Reset

228318 CVEs matched. Showing 301–350 (page 7 of 4567).

HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.

Click a column header to sort all results; click the active column again to reverse.

CVE-ID Title Severity Score (overview) NVD Score MSRC Score CNA Published Remediations Threat Source
CVE-2026-86677 Broken Authentication vulnerability HIGH 8.8 8.8 Zohocorp 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-96560 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via NCCL PD RPyC Control Channel CRITICAL 9.3 9.8 VulnCheck 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-86679 Broken Access Control vulnerability HIGH 7.1 7.1 Zohocorp 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-12974 Security Policy Bypass in Forcepoint Security Engine (NGFW) HIGH 7.9 forcepoint 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-86683 Broken Authentication Vulnerability HIGH 8.1 8.1 Zohocorp 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-96512 Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authorization HIGH 7.8 7.8 redhat 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-86681 Broken Access Control vulnerability HIGH 7.6 7.6 Zohocorp 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-86708 Sensitive data exposure CRITICAL 10.0 10.0 Zohocorp 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-95676 AuthPoint Gateway Improper Authentication in LDAP Sync Allows First-Factor Authentication Bypass HIGH 7.4 WatchGuard 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-19599 Remote Code Execution vulnerability CRITICAL 9.9 9.9 Zohocorp 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-75825 Authentication Bypass vulnerability HIGH 8.8 8.8 Zohocorp 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-86247 Apache Tomcat Native: Client certificate requirements can be down-graded 7.4 apache 2026-09-23 10 raw ·
CVE-2026-76978 Command Injection vulnerability HIGH 8.8 8.8 Zohocorp 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-86246 Apache Tomcat Native: Insecure OpenSSL options enabled 9.1 apache 2026-09-23 10 raw ·
CVE-2026-86243 Apache Tomcat Native: DoS via TLS handshake 7.5 apache 2026-09-23 10 raw ·
CVE-2026-76979 XML Injection vulnerability HIGH 7.7 7.7 Zohocorp 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-84091 SUMIT Payment Gateway for WooCommerce < 4.0.0 - Unauthenticated Payment Confirmation Forgery via bit IPN MEDIUM 5.3 5.3 WPScan 2026-09-23 10 raw ·
CVE-2026-76980 Data Exposure vulnerability HIGH 7.4 7.4 Zohocorp 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-77112 SSRF Leading to JWT Token Disclosure in Global IT Informatics' Weoll MEDIUM 6.5 6.5 TR-CERT 2026-09-23 10 raw ·
CVE-2026-84787 Privilege Escalation vulnerability HIGH 8.1 8.1 Zohocorp 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-84789 Broken Access Control vulnerability HIGH 7.1 7.1 Zohocorp 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-84791 Broken Access Control vulnerability HIGH 7.1 7.1 Zohocorp 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-80444 Unauthenticated Open Redirect Vulnerability in Abis Technology's AVESİS MEDIUM 5.4 5.4 TR-CERT 2026-09-23 10 raw ·
CVE-2026-78253 Denial-of-service (stack-exhaustion) vulnerability in QXmlStreamReader::readElementText() impacts Qt LOW 2.3 Qt 2026-09-23 10 raw ·
CVE-2026-15358 Path Traversal Vulnerability HIGH 7.5 7.5 Zohocorp 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-87022 Apache Tomcat: WebSocket message smuggling with per-message-deflate 7.5 apache 2026-09-23 10 raw ·
CVE-2026-86350 Apache Tomcat: Regression in fix for CVE-2026-41293 can trigger request header mix-up 9.1 apache 2026-09-23 10 raw ·
CVE-2026-86248 Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is di… 9.8 apache 2026-09-23 10 raw ·
CVE-2026-14913 SQL Injection vulnerability HIGH 8.8 8.8 Zohocorp 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-79677 Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout 7.5 apache 2026-09-23 10 raw ·
CVE-2026-78437 Apache Tomcat: HTTP/2 DoS via malformed request 7.3 apache 2026-09-23 10 raw ·
CVE-2026-78383 Apache Tomcat: AJP DoS via missing request body 7.5 apache 2026-09-23 10 raw ·
CVE-2026-77791 Apache Tomcat: DoS via busy wait during WebSocket close 7.5 apache 2026-09-23 10 raw ·
CVE-2026-12370 Remote Code Execution Vulnerability HIGH 7.6 7.6 Zohocorp 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-77762 Apache Tomcat: Stale HPACK emitter injects trailers into recycled pooled Request 8.1 apache 2026-09-23 10 raw ·
CVE-2026-77756 Apache Tomcat: Transfer-Encoding honored for HTTP/1.0 requests 3.7 apache 2026-09-23 10 raw ·
CVE-2026-76183 Apache Tomcat: Bypass of security constraints for WebSocket endpoints 9.8 apache 2026-09-23 10 raw ·
CVE-2026-75973 Apache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configured 7.3 apache 2026-09-23 10 raw ·
CVE-2026-96445 Keycloak-services: keycloak-services: conditional otp skip-header policy evaluated against untrusted proxy headers MEDIUM 6.8 6.8 redhat 2026-09-23 10 raw ·
CVE-2026-73581 Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore 6.5 apache 2026-09-23 10 raw ·
CVE-2026-96446 Keycloak-services: keycloak-services: par single-use bypass via prompt=none silent authentication path MEDIUM 4.2 4.2 redhat 2026-09-23 10 raw ·
CVE-2026-5696 Multiple vulnerabilities in the Microweber administration panel MEDIUM 5.9 INCIBE 2026-09-23 10 raw ·
CVE-2026-5695 Multiple vulnerabilities in the Microweber administration panel HIGH 8.4 INCIBE 2026-09-23 10 ⚠ Threat raw ·
CVE-2026-90950 Paid Member Subscriptions < 3.1.0 - Unauthenticated reCAPTCHA Bypass via Registration Form MEDIUM 5.3 5.3 WPScan 2026-09-23 10 raw ·
CVE-2026-87978 Paymob for WooCommerce < 4.1.14 - Unauthenticated Payment Bypass via Unverified Subscription Transaction Callback MEDIUM 5.3 5.3 WPScan 2026-09-23 10 raw ·
CVE-2026-87848 MPCX Lightbox 1.2.2 - 1.2.5 - Unauthenticated Non-Public Post Content Disclosure LOW 3.7 3.7 WPScan 2026-09-23 10 raw ·
CVE-2026-87071 Forminator Forms < 1.57.2.1 - Unauthenticated Post Meta Injection on Submitted Posts MEDIUM 5.3 5.3 WPScan 2026-09-23 10 raw ·
CVE-2026-87070 Forminator Forms < 1.57.2.1 - Unauthenticated Poll Vote Limit Bypass via IP Spoofing MEDIUM 5.3 5.3 WPScan 2026-09-23 10 raw ·
CVE-2026-86612 Ninja Tables < 5.2.17 - Unauthenticated Arbitrary Shortcode Execution via Fluent Forms Data Source MEDIUM 5.6 5.6 WPScan 2026-09-23 10 raw ·
CVE-2026-86604 GTranslate < 5.0.1 - Unauthenticated Arbitrary Shortcode Execution via Email Translation MEDIUM 4.8 4.8 WPScan 2026-09-23 10 raw ·