Skip to main content

Severity archive

High severity CVEs

High

126,461 high severity CVEs — 43,866 Critical, 126,461 High, 163,873 Medium, 18,049 Low, 1,893 Unrated across the current result set.

CVE-2026-49744

Published Jul 24, 2026

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Ou…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-49743

Published Jul 24, 2026

Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/wri…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-16519

Published Jul 24, 2026

A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe sear…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-14603

Published Jul 24, 2026

The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-14172

Published Jul 24, 2026

Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-12981

Published Jul 24, 2026

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the passw…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-12497

Published Jul 24, 2026

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-16870

Published Jul 24, 2026

Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overf…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-66141

Published Jul 24, 2026

Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-66140

Published Jul 24, 2026

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-66138

Published Jul 24, 2026

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciousl…

CVSS 7.2 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-12736

Published Jul 24, 2026

The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::save_option() REST route (POST /…

CVSS 8.0 · High
evidence mentions
9
Buzz score
34.5

CVE-2026-56167

Published Jul 24, 2026

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-35425

Published Jul 24, 2026

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-50044

Published Jul 23, 2026

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin credentials via weak hash or a pas…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-40430

Published Jul 23, 2026

Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API.

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-65694

Published Jul 23, 2026

Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplyi…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-65604

Published Jul 23, 2026

Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-63313

Published Jul 23, 2026

9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controlled url parameter and passes it…

CVSS 8.3 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-16807

Published Jul 23, 2026

Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium securit…

CVSS 8.8 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-16806

Published Jul 23, 2026

Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security…

CVSS 8.8 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-16805

Published Jul 23, 2026

Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security s…

CVSS 8.8 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-16804

Published Jul 23, 2026

Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a c…

CVSS 8.3 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2024-58354

Published Jul 23, 2026

cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_ta…

CVSS 8.5 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-6924

Published Jul 23, 2026

A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers.…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0
Showing 876-900 of 126,461 CVEsPage 36 of 5059