Skip to main content

Severity archive

High severity CVEs

High

124,775 high severity CVEs — 43,370 Critical, 124,775 High, 163,219 Medium, 17,939 Low, 2,047 Unrated across the current result set.

CVE-2026-12341

Published Jul 20, 2026

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bea…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-8170

Published Jul 20, 2026

The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links outside of the intended privil…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-8169

Published Jul 20, 2026

ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The challenge value is generated using an insufficiently random so…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-64612

Published Jul 20, 2026

A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image fi…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-55626

Published Jul 20, 2026

xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using the Xvnc backend over UNIX domain sockets, the Xvnc proces…

CVSS 8.0 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-48812

Published Jul 20, 2026

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's attachment download route skips token authentication for a…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-34239

Published Jul 20, 2026

Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax.php path. This endpoint is protected only by `api_protect_…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-58484

Published Jul 20, 2026

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()` reads each backup's `_manifest.json` and trusts the manife…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-54538

Published Jul 20, 2026

xrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered where the software fails to properly validate the totalLength field within the RDP protoc…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-46701

Published Jul 20, 2026

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.4.5, the MCP SSE server defaults to an empty secret (`process.env['NETWORK_AI_MCP_SECRET'] ?? ''` a…

CVSS 7.6 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-46555

Published Jul 20, 2026

WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the `whatsapp-bridge` HTTP A…

CVSS 7.7 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-44178

Published Jul 20, 2026

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding da…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-41521

Published Jul 20, 2026

xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A…

CVSS 8.2 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-40187

Published Jul 20, 2026

In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTemplate XML file (`.xet`) to the…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-39879

Published Jul 20, 2026

Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), sysl…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-39385

Published Jul 20, 2026

Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-35591

Published Jul 20, 2026

libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number o…

CVSS 7.0 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-33327

Published Jul 20, 2026

libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions lea…

CVSS 7.0 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-32825

Published Jul 20, 2026

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framew…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-32824

Published Jul 20, 2026

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framew…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-32821

Published Jul 20, 2026

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framew…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-32820

Published Jul 20, 2026

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framew…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-32806

Published Jul 20, 2026

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framew…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-63429

Published Jul 20, 2026

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` re…

CVSS 8.6 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-46415

Published Jul 20, 2026

The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address. Prior to version 0.10.1, Caddy Defender use…

CVSS 8.2 · High
evidence mentions
4
Buzz score
26.1
Showing 751-775 of 124,775 CVEsPage 31 of 4991