CVEs
Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.
228318 CVEs matched. Showing 351–400 (page 8 of 4567).
HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.
Click a column header to sort all results; click the active column again to reverse.
| CVE-ID ↕ | Title ↕ | Severity ↕ | Score (overview) ↕ | NVD Score | MSRC Score | CNA ↕ | Published ↕ | Remediations | Threat | Source |
|---|---|---|---|---|---|---|---|---|---|---|
CVE-2026-86601 |
WP Recipe Maker < 10.8.2 - Unauthenticated Arbitrary Shortcode Execution via Comment Content | MEDIUM | 6.5 | 6.5 | — | WPScan | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-96442 |
Emacs: emacs: arbitrary code execution, incomplete fix for cve-2024-53920 | HIGH | 7.8 | 7.8 | — | redhat | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96456 |
Reachy Mini Bluetooth PIN authentication can be bypassed by racing an authenticated device | MEDIUM | 6.3 | 6.3 | — | JFROG | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-96455 |
Reachy Mini daemon allows unauthenticated remote code execution through the app installation endpoint | HIGH | 8.8 | 8.8 | — | JFROG | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96454 |
Pake grants unrestricted IPC access to every HTTPS origin loaded in generated applications | HIGH | 8.2 | 8.2 | — | JFROG | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-79616 |
Out-of-bounds read vulnerability in Context2D.path and PathSvg.path properties impacts Qt Quick | LOW | 0.6 | — | — | Qt | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-94243 |
Apache Sling Security Bundle: RefererFilter accepts weaker-than-origin evidence | — | — | 7.3 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-95627 |
Tauri framework v2 Dialog plugin auto-expands the filesystem scope with attacker-controlled recursion | HIGH | 7.7 | 7.7 | — | JFROG | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94251 |
Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource | — | — | 6.5 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-91928 |
Apache Sling XSS: Sanitizer bypass, uncontrolled resource consumption and failure pf protection mechanisms | — | — | 6.1 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-96443 |
Apache Doris: JDBC driver URL validation bypass leads to remote code execution | — | — | 6.5 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-95626 |
Tauri framework v2 CSP nonce protection bypass via data and blob URI schemes allows an XSS to RCE chains | HIGH | 8.3 | 8.3 | — | JFROG | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91852 |
Apache Sling XSS: CWE-79 multiple raw-string break-outs and ReDOS in XSSImpl | — | — | 6.1 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-91999 |
Apache Sling XSS: Improper escaping in the XSS Webconsole plugin | — | — | 6.1 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-92001 |
Apache Sling XSS: Missing parser resource limits | — | — | 6.1 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-73192 |
Apache Sling XSS: XSS possible through XSSAPI.getValidHref() | — | — | 6.1 | — | apache | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-31377 |
Apache Doris: Improper Authentication Allows Unauthorized Access to FE Meta Service | HIGH | 7.5 | 7.5 | — | apache | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-42801 |
Deference after null check in as_rrc | HIGH | 7.4 | 7.4 | — | ASR | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95625 |
Tauri framework v2 missing updater signature version number validation can be exploited into forced downgrade | MEDIUM | 5.9 | 5.9 | — | JFROG | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-93368 |
Rename wp-login.php to anything you want <= 2.0.1 - Unauthenticated SQL Injection via 'log' (Username) Parameter | HIGH | 7.5 | 7.5 | — | Wordfence | 2026-09-23 | 1 | ⚠ Threat | raw · ⬇ |
CVE-2026-15027 |
Changing|CGServiSign - OS Command Injection | HIGH | 8.6 | 8.8 | — | twcert | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91788 |
Foxit PDF Editor/Reader Missing Authorization Information Disclosure Vulnerability | MEDIUM | 4.7 | 4.7 | — | Foxit | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-91790 |
Foxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91791 |
Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91792 |
Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91793 |
Foxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91794 |
Foxit PDF Editor/Reader DeviceN Colorspace Out-Of-Bounds Write Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91795 |
Foxit PDF Editor/Reader FileOpen Uninitialized Variable Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91796 |
Foxit PDF Editor/Reader importIcon NTLM Response Information Disclosure Vulnerability | MEDIUM | 6.1 | 6.1 | — | Foxit | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-91797 |
Foxit PDF Editor/Reader Portfolio Directory Traversal Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91799 |
Foxit Editor/Reader Array resetForm Use-After-Free Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91805 |
Use-after-free Vulnerability in Foxit PDF Editor/Reader Page-tree Handling | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91800 |
Foxit PDF Editor installer local privilege escalation | HIGH | 8.8 | 8.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91801 |
Foxit PDF Editor/Reader RichMedia Annotation Directory Traversal Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91802 |
Foxit PDF Editor/Reader — Heap Buffer Overflow in WebP Image Decoding via Bitmap Stride Confusion | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91804 |
Foxit PDF Editor/Reader Out-of-bounds Write Vulnerability While Rendering | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91806 |
Foxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91807 |
Foxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability | MEDIUM | 6.1 | 6.1 | — | Foxit | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-91798 |
Foxit PDF Editor/Reader Updater Privilege Escalation | HIGH | 8.8 | 8.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91803 |
Security Vulnerability Report – Foxit PDF Editor/Reader Updater DLL Search Path Hijacking | HIGH | 8.8 | 8.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91808 |
Foxit PDF Editor/Reader JPEG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability | MEDIUM | 6.1 | 6.1 | — | Foxit | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-91810 |
Foxit PDF Editor/Reader Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability | MEDIUM | 6.1 | 6.1 | — | Foxit | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-91811 |
Foxit PDF Editor/Reader PRC Stream Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91812 |
Foxit PDF Editor/Reader FoxitUpdater Improper Certificate Validation Local Privilege Escalation Vulnerability | HIGH | 7.9 | 7.9 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91813 |
Foxit PDF Editor/Reader FoxitUpdater Race Condition Local Privilege Escalation Vulnerability | HIGH | 8.8 | 8.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91815 |
Foxit PDF Editor/Reader JPEG2000 Parsing Memory Corruption Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91814 |
Security vulnerability: Foxit PDF Editor/Reader Fails to Detect Modifications to Signed Documents Displaying Newly Added… | MEDIUM | 5.3 | 5.3 | — | Foxit | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-91816 |
Foxit PDF Editor/Reader AcroForm Use-After-Free Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-91817 |
Foxit PDF Editor/Reader AcroForm Out-of-Bounds Read Remote Code Execution Vulnerability | MEDIUM | 6.1 | 6.1 | — | Foxit | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-91818 |
Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability | HIGH | 7.8 | 7.8 | — | Foxit | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |