Skip to main content

Severity archive

High severity CVEs

High

124,781 high severity CVEs — 43,370 Critical, 124,781 High, 163,227 Medium, 17,939 Low, 2,051 Unrated across the current result set.

CVE-2026-32824

Published Jul 20, 2026

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framew…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-32821

Published Jul 20, 2026

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framew…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-32820

Published Jul 20, 2026

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framew…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-32806

Published Jul 20, 2026

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framew…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-63429

Published Jul 20, 2026

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` re…

CVSS 8.6 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-46415

Published Jul 20, 2026

The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address. Prior to version 0.10.1, Caddy Defender use…

CVSS 8.2 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-45713

Published Jul 20, 2026

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that controls the maximum allowed DATA pay…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-32807

Published Jul 20, 2026

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framew…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-28220

Published Jul 20, 2026

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-27823

Published Jul 20, 2026

A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands on the ser…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-25039

Published Jul 20, 2026

Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanitize the workspace name, creating a vulnerability if that wo…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-21824

Published Jul 20, 2026

HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative ope…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-63091

Published Jul 20, 2026

ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attack…

CVSS 7.1 · High
evidence mentions
6
Buzz score
26.0

CVE-2026-63090

Published Jul 20, 2026

ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitra…

CVSS 8.7 · High
evidence mentions
6
Buzz score
26.0

CVE-2026-62418

Published Jul 20, 2026

Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue affects Apache Syncope: from 3.0…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-54910

Published Jul 20, 2026

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-cont…

CVSS 7.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-52349

Published Jul 20, 2026

Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute arbitrary code via the Spooner file mana…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-46410

Published Jul 20, 2026

FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may leak some sensitive info, such as source and path. Versions 1…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-45270

Published Jul 20, 2026

CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-ke…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-16248

Published Jul 20, 2026

A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. Th…

CVSS 7.4 · High
evidence mentions
6
Buzz score
31.0

CVE-2026-12080

Published Jul 20, 2026

A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic…

CVSS 7.3 · High
evidence mentions
4
Buzz score
32.6

CVE-2026-64623

Published Jul 20, 2026

Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accepts any non-empty string as val…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-63763

Published Jul 20, 2026

SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileged users (e.g., those with the database editor role) can cr…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-63760

Published Jul 20, 2026

SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or parentheses. Unauthenticated…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-63759

Published Jul 20, 2026

SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annotations. Authenticated attackers can send queries with deepl…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort
Showing 776-800 of 124,781 CVEsPage 32 of 4992