Skip to main content

Severity archive

High severity CVEs

High

124,788 high severity CVEs — 43,374 Critical, 124,788 High, 163,241 Medium, 17,941 Low, 2,067 Unrated across the current result set.

CVE-2026-45270

Published Jul 20, 2026

CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-ke…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-16248

Published Jul 20, 2026

A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. Th…

CVSS 7.4 · High
evidence mentions
6
Buzz score
31.0

CVE-2026-12080

Published Jul 20, 2026

A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic…

CVSS 7.3 · High
evidence mentions
4
Buzz score
32.6

CVE-2026-64623

Published Jul 20, 2026

Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accepts any non-empty string as val…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-63763

Published Jul 20, 2026

SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileged users (e.g., those with the database editor role) can cr…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-63760

Published Jul 20, 2026

SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or parentheses. Unauthenticated…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-63759

Published Jul 20, 2026

SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annotations. Authenticated attackers can send queries with deepl…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-63757

Published Jul 20, 2026

SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns attached session UUIDs without authentication and accepts arb…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-63755

Published Jul 20, 2026

SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses in UPDATE, UPSERT, INSERT ON DUPLICATE KEY UPDATE, and RELAT…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-63754

Published Jul 20, 2026

SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WHERE clauses that evaluate to errors cause all CREATE, UPDATE, and DEL…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-63747

Published Jul 20, 2026

SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is set without a namespace. Unauthenticated attackers can send…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-63746

Published Jul 20, 2026

SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references. Authenticated users can read records from any table reacha…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-63740

Published Jul 20, 2026

SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users, leaking denied array elements instead of hiding them. Att…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-63739

Published Jul 20, 2026

SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows database users with EDITOR or OWNER roles to read files acces…

CVSS 8.3 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-63737

Published Jul 20, 2026

SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server with queries containing long chains of operators. Attacker…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-63735

Published Jul 20, 2026

SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticated users to invoke endpoints in different namespaces/databa…

CVSS 8.6 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-16247

Published Jul 20, 2026

In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this process, existing permissions on %ProgramData% are deleted and re…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-16246

Published Jul 20, 2026

In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows group Everyone is granted full control over %ProgramData% in…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-14448

Published Jul 20, 2026

An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certificates view due to improper neutralization of special elemen…

CVSS 8.6 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-13577

Published Jul 20, 2026

Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently fall…

CVSS 8.2 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-9833

Published Jul 20, 2026

The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters before reflecting it in the res…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-6656

Published Jul 20, 2026

Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This allows discrepancies in timing to…

CVSS 7.5 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-13142

Published Jul 20, 2026

The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-pa…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-12970

Published Jul 20, 2026

The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that execut…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-12592

Published Jul 20, 2026

The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthent…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Showing 801-825 of 124,788 CVEsPage 33 of 4992