CVEs
Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.
228318 CVEs matched. Showing 1–50 (page 1 of 4567).
HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.
Click a column header to sort all results; click the active column again to reverse.
| CVE-ID ↕ | Title ↕ | Severity ↕ | Score (overview) ↕ | NVD Score | MSRC Score | CNA ↕ | Published ↕ | Remediations | Threat | Source |
|---|---|---|---|---|---|---|---|---|---|---|
CVE-2026-96803 |
java110 MicroCommunity fallBack API Endpoint BusinessApi.java QueryServiceSMOImpl.fallBack sql injection | MEDIUM | 6.9 | 7.3 | — | VulDB | 2026-09-24 | — | — | raw · ⬇ |
CVE-2026-18467 |
Paytium: Mollie payment forms & donations <= 5.0.3 - Unauthenticated Privilege Escalation via 'pt_form_field[pt-user-rol… | CRITICAL | 9.8 | 9.8 | — | Wordfence | 2026-09-24 | 1 | ⚠ Threat | raw · ⬇ |
CVE-2026-96777 |
Forma LMS Multi-User-Selector AJAX Endpoint getData getDataTask sql injection | MEDIUM | 5.3 | 6.3 | — | VulDB | 2026-09-24 | — | — | raw · ⬇ |
CVE-2026-96774 |
SPON Communications IP Network Audio Device XC-9603 Configuration File Download sys_cfg.txt loadCfg information disclosu… | MEDIUM | 6.9 | 5.3 | — | VulDB | 2026-09-24 | — | — | raw · ⬇ |
CVE-2026-96773 |
Intelliants Subrion CMS Login Page login.php authorize redirect | MEDIUM | 5.3 | 4.3 | — | VulDB | 2026-09-24 | — | — | raw · ⬇ |
CVE-2026-96772 |
Intelliants Subrion CMS actions.json assign-owner information disclosure | MEDIUM | 6.9 | 5.3 | — | VulDB | 2026-09-24 | — | — | raw · ⬇ |
CVE-2026-96764 |
kvcache-ai mooncake Regular Expression GetReplicaListByRegex allocation of resources | MEDIUM | 5.3 | 4.3 | — | VulDB | 2026-09-24 | — | — | raw · ⬇ |
CVE-2026-96763 |
kvcache-ai mooncake MountSegment Request Processing segment.cpp access control | MEDIUM | 5.3 | 5.4 | — | VulDB | 2026-09-24 | — | — | raw · ⬇ |
CVE-2026-96762 |
kvcache-ai mooncake RPC Path UnmountSegment authorization | MEDIUM | 6.9 | 7.3 | — | VulDB | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-82370 |
Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service | HIGH | 8.6 | — | — | brocade | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-96751 |
pmTicket Project-Management-Software add_project.php setSync sql injection | MEDIUM | 6.9 | 7.3 | — | VulDB | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-96739 |
SEMCMS KindEditor Upload upload_json.php cross site scripting | MEDIUM | 5.3 | 4.3 | — | VulDB | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-89078 |
Double Free in GitLab | CRITICAL | 9.9 | — | — | GitLab | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-92530 |
Use of Less Trusted Source in GitLab | MEDIUM | 4.3 | 4.3 | — | GitLab | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-92470 |
Missing Authorization in GitLab | HIGH | 7.7 | 7.7 | — | GitLab | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-92529 |
Incorrect Authorization in GitLab | MEDIUM | 4.3 | 4.3 | — | GitLab | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-92874 |
Incorrect Authorization in GitLab | MEDIUM | 5.4 | 5.4 | — | GitLab | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-92628 |
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in GitLab | LOW | 3.1 | 3.1 | — | GitLab | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-93577 |
Integer Overflow or Wraparound in GitLab | CRITICAL | 9.9 | 9.9 | — | GitLab | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-96680 |
ByteDance Coze Scraper Extension External Message index.js chrome.runtime.onMessageExternal.addListener authorization | MEDIUM | 5.3 | 4.3 | — | VulDB | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-96678 |
weiqingwen spring-boot-forum Avatar Upload NewUserFormValidator.java validate path traversal | MEDIUM | 5.3 | 6.3 | — | VulDB | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-70125 |
Microsoft Outlook Remote Code Execution Vulnerability | HIGH | 8.8 | 8.8 | 8.8 | microsoft | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-96676 |
Fast FAC1900R uhttpd get_alias_name stack-based overflow | MEDIUM | 5.3 | 6.3 | — | VulDB | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-96606 |
LB-Link BL-CPE600EU Configuration Backup Mifi_config.bin information disclosure | MEDIUM | 6.9 | 5.3 | — | VulDB | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-59980 |
hpack: Unbounded variable integer decoding can cause run-away computation on malformed input | MEDIUM | 6.3 | — | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-96604 |
SoftNews Media Group DataLife Engine Search search.php strip_data sql injection | MEDIUM | 6.9 | 7.3 | — | VulDB | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-96603 |
Abdurrab5 online-makeup-store Admin functions.php confirm_user authorization | MEDIUM | 6.9 | 7.3 | — | VulDB | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-81537 |
DataStage on Cloud Pak for Data has several vulnerabilities | HIGH | 8.8 | 8.8 | — | ibm | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-81536 |
DataStage on Cloud Pak for Data has several vulnerabilities | HIGH | 7.7 | 7.7 | — | ibm | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-81208 |
DataStage on Cloud Pak for Data has several vulnerabilities | HIGH | 7.7 | 7.7 | — | ibm | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-93352 |
Laravel-Mediable 7.0.0 < 7.0.2 RCE via .pht File Upload | CRITICAL | 9.3 | 9.8 | — | VulnCheck | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-80423 |
DataStage on Cloud Pak for Data has several vulnerabilities | HIGH | 8.8 | 8.8 | — | ibm | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-86583 |
Import and export users and customers <= 2.4.17 - Authenticated (Subscriber+) Privilege Escalation via CSV Escape-Charac… | HIGH | 8.8 | 8.8 | — | Wordfence | 2026-09-23 | 1 | ⚠ Threat | raw · ⬇ |
CVE-2026-19125 |
EthPress <= 2.3.5 - Unauthenticated Authentication Bypass | HIGH | 8.1 | 8.1 | — | Wordfence | 2026-09-23 | 1 | ⚠ Threat | raw · ⬇ |
CVE-2026-75887 |
Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handler | HIGH | 7.5 | 7.5 | — | redhat | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-96602 |
Abdurrab5 online-makeup-store Customer Login customerSignin.php sql injection | MEDIUM | 6.9 | 7.3 | — | VulDB | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-96601 |
Abdurrab5 online-makeup-store Admin Login index.php sql injection | MEDIUM | 6.9 | 7.3 | — | VulDB | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-80425 |
DataStage on Cloud Pak for Data has several vulnerabilities | HIGH | 8.8 | 8.8 | — | ibm | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-80412 |
DataStage on Cloud Pak for Data has several vulnerabilities | HIGH | 8.8 | 8.8 | — | ibm | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-80379 |
DataStage on Cloud Pak for Data has several vulnerabilities | HIGH | 8.8 | 8.8 | — | ibm | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-6935 |
Multiple Vulnerabilities in IBM Concert Software | HIGH | 7.8 | 7.8 | — | ibm | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-6928 |
Multiple Vulnerabilities in IBM Concert Software | CRITICAL | 9.8 | 9.8 | — | ibm | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-6925 |
Multiple Vulnerabilities in IBM Concert Software | MEDIUM | 5.3 | 5.3 | — | ibm | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-6794 |
Multiple Vulnerabilities in IBM Concert Software | HIGH | 7.8 | 7.8 | — | ibm | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-67221 |
RabbitMQ: AMQP 1.0 shovel status exposes plaintext URI passwords | MEDIUM | 5.9 | — | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-75886 |
Openshift/console: openshift/console: unauthenticated reverse proxy to in-cluster catalogd service with session token fo… | HIGH | 7.2 | 7.2 | — | redhat | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-67231 |
RabbitMQ: Trust-store whitelist by Issuer+Serial only | CRITICAL | 9.1 | — | — | GitHub_M | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-67218 |
RabbitMQ: Super-stream HTTP creation skips configure-permission check | LOW | 2.1 | — | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-6730 |
Multiple Vulnerabilities in IBM Concert Software | CRITICAL | 9.8 | 9.8 | — | ibm | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |
CVE-2026-6721 |
Multiple Vulnerabilities in IBM Concert Software | CRITICAL | 9.8 | 9.8 | — | ibm | 2026-09-23 | — | ⚠ Threat | raw · ⬇ |