Skip to main content

Severity archive

High severity CVEs

High

128,439 high severity CVEs — 44,420 Critical, 128,439 High, 163,559 Medium, 18,236 Low, 2,076 Unrated across the current result set.

CVE-2026-63550

Published Jul 30, 2026

The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-63362

Published Jul 30, 2026

An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cause a denial of service via a crafted UDP packet.

CVSS 8.2 · High
evidence mentions
7
Buzz score
35.8

CVE-2026-63035

Published Jul 30, 2026

A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of service or potentially execute arb…

CVSS 7.2 · High
evidence mentions
7
Buzz score
35.8

CVE-2026-64816

Published Jul 30, 2026

RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs. On Windows, a UNC path in lutPath causes an outbo…

CVSS 7.1 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-63559

Published Jul 30, 2026

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sens…

CVSS 8.7 · High
evidence mentions
7
Buzz score
35.8

CVE-2026-62246

Published Jul 30, 2026

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lo…

CVSS 8.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-5846

Published Jul 30, 2026

The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS c…

CVSS 7.6 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-18064

Published Jul 30, 2026

An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions thr…

CVSS 8.2 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-12562

Published Jul 30, 2026

The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system. This vulnerabil…

CVSS 8.7 · High
evidence mentions
6
Buzz score
34.5

CVE-2026-68500

Published Jul 30, 2026

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment w…

CVSS 7.5 · High
evidence mentions
10
Buzz score
29.0

CVE-2026-55768

Published Jul 30, 2026

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11, the built-in WebSocket serve…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-54715

Published Jul 30, 2026

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matche…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-67527

Published Jul 30, 2026

OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} accepted _links.fileLinks and allowed authenticated users with…

CVSS 7.6 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-67207

Published Jul 30, 2026

Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup f…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-67206

Published Jul 30, 2026

Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting mi…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-11536

Published Jul 30, 2026

IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-66416

Published Jul 30, 2026

Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excl…

CVSS 8.6 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-66415

Published Jul 30, 2026

Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized…

CVSS 8.4 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-61536

Published Jul 30, 2026

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} bloc…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-18140

Published Jul 30, 2026

Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct dese…

CVSS 8.7 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-15978

Published Jul 30, 2026

SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-15977

Published Jul 30, 2026

SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the --admin-api-key is configured.

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-13444

Published Jul 30, 2026

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matching Chroma persist_directory and…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-12942

Published Jul 30, 2026

IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot d…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-12733

Published Jul 30, 2026

IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 976-1,000 of 128,439 CVEsPage 40 of 5138