Skip to main content

Severity archive

High severity CVEs

High

129,671 high severity CVEs — 44,698 Critical, 129,671 High, 164,548 Medium, 18,354 Low, 2,644 Unrated across the current result set.

CVE-2026-72562

Published Aug 11, 2026

An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via the DataObject grid id column…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72561

Published Aug 11, 2026

A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfigure the platform global OIDC/…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72558

Published Aug 11, 2026

An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE clause. The clause concatenates a…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72557

Published Aug 11, 2026

An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP scripts via the asset upload endpoint. The…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72556

Published Aug 11, 2026

A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by exploiting a broken permission check in the Filter class. The c…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72555

Published Aug 11, 2026

A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.roles_active flag defaults to false, causing all permission che…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72552

Published Aug 11, 2026

A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or externa…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72551

Published Aug 11, 2026

A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with the Developer role to execute arbitrary OS commands by exploiting a PHP-Sandbox allow-li…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72548

Published Aug 11, 2026

An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any organisation tenant record via the gettenan…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72547

Published Aug 11, 2026

An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event organiser to bulk import attendees into events belonging to ot…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72546

Published Aug 11, 2026

An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event organiser to inject attendees and orders into events belonging…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72545

Published Aug 11, 2026

An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any contact record via the updatecont…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72544

Published Aug 11, 2026

An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to forge document audit-trail entries via the triggerevent…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72543

Published Aug 11, 2026

An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any contact record via the getcontact…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72538

Published Aug 11, 2026

An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code execution via the git_clone pull step branch field. The br…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72537

Published Aug 11, 2026

A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72536

Published Aug 11, 2026

A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to manipulate any tenant Stripe subscription via the stripeCreateI…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72535

Published Aug 11, 2026

A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint Stripe Billing Portal sessions for any tenant via the stri…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72534

Published Aug 11, 2026

A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to gain superuser privileges…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72533

Published Aug 11, 2026

An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL n…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-50237

Published Aug 11, 2026

A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitr…

CVSS 7.4 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-50236

Published Aug 11, 2026

An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutrali…

CVSS 7.4 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-13739

Published Aug 11, 2026

A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software custo…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-73160

Published Aug 11, 2026

Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints. The URL validation routine checked whether a supplie…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72694

Published Aug 11, 2026

A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink)…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Showing 1,026-1,050 of 129,671 CVEsPage 42 of 5187