Skip to main content

Severity archive

High severity CVEs

High

129,671 high severity CVEs — 44,698 Critical, 129,671 High, 164,548 Medium, 18,355 Low, 2,644 Unrated across the current result set.

CVE-2026-72693

Published Aug 11, 2026

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the owne…

CVSS 7.8 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-71217

Published Aug 11, 2026

A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len…

CVSS 7.5 · High
evidence mentions
3
Buzz score
21.9

CVE-2026-15567

Published Aug 11, 2026

A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without boun…

CVSS 7.5 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-15565

Published Aug 11, 2026

A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method.…

CVSS 7.5 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-15563

Published Aug 11, 2026

A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a m…

CVSS 7.4 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-15562

Published Aug 11, 2026

A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OO…

CVSS 7.5 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-15561

Published Aug 11, 2026

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JV…

CVSS 7.5 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-15560

Published Aug 11, 2026

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to l…

CVSS 8.1 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-15556

Published Aug 11, 2026

A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML res…

CVSS 8.1 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-15555

Published Aug 11, 2026

A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filt…

CVSS 8.8 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-15554

Published Aug 11, 2026

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direc…

CVSS 7.4 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-19418

Published Aug 11, 2026

The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool ap…

CVSS 7.3 · High
evidence mentions
5
Buzz score
27.9

CVE-2026-16053

Published Aug 11, 2026

Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-4757

Published Aug 11, 2026

A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can only be exploited after authenti…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-8917

Published Aug 11, 2026

Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an arbitrary me…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-19424

Published Aug 11, 2026

Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-66763

Published Aug 11, 2026

SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high pr…

CVSS 7.9 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-58243

Published Aug 11, 2026

SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database ope…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-58230

Published Aug 11, 2026

SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensiti…

CVSS 7.0 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-44765

Published Aug 11, 2026

Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related applicatio…

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-44764

Published Aug 11, 2026

Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet u…

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-44763

Published Aug 11, 2026

SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploi…

CVSS 7.6 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-8718

Published Aug 10, 2026

tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval…

CVSS 8.4 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-30241

Published Aug 10, 2026

Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to system-level command execution f…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-30239

Published Aug 10, 2026

In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to de…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Showing 1,051-1,075 of 129,671 CVEsPage 43 of 5187