Skip to main content

Severity archive

High severity CVEs

High

128,299 high severity CVEs — 44,336 Critical, 128,299 High, 163,420 Medium, 18,181 Low, 1,703 Unrated across the current result set.

CVE-2026-58043

Published Jul 30, 2026

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47882

Published Jul 30, 2026

When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47873

Published Jul 30, 2026

The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback.…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47858

Published Jul 30, 2026

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affe…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-16529

Published Jul 30, 2026

A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affe…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-16527

Published Jul 30, 2026

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric…

CVSS 7.3 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-16526

Published Jul 30, 2026

A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitr…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-16524

Published Jul 30, 2026

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute a…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-15240

Published Jul 30, 2026

The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operator who initiated it, allowing a lower-privileged account…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-14239

Published Jul 30, 2026

The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken from a request parameter, and does not escape that label when…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-13395

Published Jul 30, 2026

The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-13178

Published Jul 30, 2026

The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orde…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-12687

Published Jul 30, 2026

The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-12500

Published Jul 30, 2026

The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, al…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-67248

Published Jul 30, 2026

A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because user-controlled input is not properly validated before bein…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-67247

Published Jul 30, 2026

A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlled disk serial input is not sufficiently validated before be…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-67245

Published Jul 30, 2026

A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled certificate name input is not sufficiently validated befor…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-1360

Published Jul 30, 2026

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_fiel…

CVSS 7.5 · High
evidence mentions
9
Buzz score
43.0

CVE-2026-14356

Published Jul 30, 2026

The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin not properly verifying that a…

CVSS 8.8 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-67244

Published Jul 30, 2026

A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user-controlled notification configuration input may be process…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-18188

Published Jul 30, 2026

A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled rsync backup configuration or log data may be processed th…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-18187

Published Jul 30, 2026

A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled task input may be included in an error response and pro…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-18186

Published Jul 30, 2026

A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled backup configuration data may be written into a task…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-16727

Published Jul 30, 2026

Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privi…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Showing 926-950 of 128,299 CVEsPage 38 of 5132