Security Risk Severity
High Security Risks — Page 13
Published vulnerability pages grouped by high severity. Use this page to review risks that need similar prioritization.
872 published high risks
High severity
Showing 433–468 of 872 published risks.
CVE-2026-59836 in FortiClient EMS
A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>
Updated Jul 15, 2026
CVE-2026-54433 in Roundcube Webmail
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or...
Updated Jul 15, 2026
CVE-2026-45074 in Symfony Security HTTP
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter from Request::getSchemeAndHttpHost(), which reflects an attacker-controlled...
Updated Jul 15, 2026
CVE-2026-45077 in Symfony Monolog Bridge
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default and...
Updated Jul 15, 2026
CVE-2026-45756 in Symfony JSON Path
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until 7.4.12 and 8.0.12, the JsonPath component compiles attacker-controlled match() and search() filter patterns directly into preg_match()...
Updated Jul 15, 2026
CVE-2026-55021 in Microsoft SharePoint Server
Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.
Updated Jul 15, 2026
CVE-2026-55034 in Microsoft SharePoint Server
Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.
Updated Jul 15, 2026
CVE-2026-55947 in Microsoft Excel / Microsoft 365 Apps
Microsoft Excel has a memory corruption issue that can let an attacker run code when a user opens a malicious file.
Updated Jul 15, 2026
CVE-2026-55949 in Microsoft Excel / Microsoft 365 Apps
Microsoft Excel has an uninitialized resource issue that can let an attacker run code when a user opens a malicious file.
Updated Jul 15, 2026
CVE-2026-56156 in Microsoft Excel / Microsoft 365 Apps
Microsoft Excel has a memory corruption issue that can let an attacker run code when a user opens a malicious file.
Updated Jul 15, 2026
CVE-2026-58277 in Microsoft SharePoint Server
Microsoft SharePoint Server has an authorization issue that can let an authorized attacker gain higher privileges over the network.
Updated Jul 15, 2026
CVE-2026-45069 in Symfony Security HTTP
Symfony Security HTTP can accept OIDC tokens that miss required audience, issuer, or expiry claims.
Updated Jul 15, 2026
CVE-2026-45075 in Symfony Security HTTP
Symfony Security HTTP can let HEAD requests bypass checks that only allow GET requests.
Updated Jul 15, 2026
CVE-2026-45133 in Symfony YAML
Symfony YAML can crash a worker when it parses very deeply nested YAML input.
Updated Jul 15, 2026
CVE-2026-45304 in Symfony YAML
Symfony YAML can use too much memory when crafted aliases expand recursively.
Updated Jul 15, 2026
CVE-2026-45305 in Symfony YAML
Symfony YAML can hang on crafted YAML because of slow regex backtracking.
Updated Jul 15, 2026
CVE-2026-45071 in Symfony DomCrawler
Symfony DomCrawler can read local files when it parses attacker-controlled XML content.
Updated Jul 15, 2026
CVE-2026-47984 in Adobe Commerce
Adobe Commerce has an authorization issue that can let an attacker gain unauthorized read and write access.
Updated Jul 15, 2026
CVE-2026-47988 in Adobe Commerce
Adobe Commerce has an authorization issue that can let an attacker gain unauthorized read and write access.
Updated Jul 15, 2026
CVE-2026-47992 in Adobe Commerce
Adobe Commerce has a SQL injection issue that can lead to code execution for a high-privilege attacker.
Updated Jul 15, 2026
CVE-2026-47994 in Adobe Commerce
Adobe Commerce has a stored XSS issue that can help an attacker gain more access through a victim browser.
Updated Jul 15, 2026
CVE-2026-47995 in Adobe Commerce
Adobe Commerce has a stored XSS issue that can help an attacker gain more access through a victim browser.
Updated Jul 15, 2026
CVE-2026-47996 in Adobe Commerce
Adobe Commerce has an authorization issue that can let a high-privilege attacker bypass rules and read data.
Updated Jul 15, 2026
CVE-2026-48489 in Symfony Security HTTP
Symfony Security HTTP can let a failed login request reach protected GET routes when failure forwarding is enabled.
Updated Jul 15, 2026
Unlimited Elements For Elementor <= 2.0.12 - Unauthenticated Stored Cross-Site Scripting
Unlimited Elements For Elementor has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
Database for Contact Form 7, WPforms, Elementor forms <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting
Database for Contact Form 7, WPforms, Elementor forms has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
Document Gallery <= 5.1.0 - Unauthenticated Stored Cross-Site Scripting
Document Gallery has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting
NEX-Forms – Ultimate Forms Plugin for WordPress has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.6 - Unauthenticated Stored Cross-Site Scripting
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.15.0.8 - Unauthenticated Stored Cross-Site Scripting
FunnelKit – Funnel Builder for WooCommerce Checkout has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
ICS Calendar <= 12.1.1 - Unauthenticated Stored Cross-Site Scripting
ICS Calendar has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
WC Shop Sync – Square Payment Gateway and Product Synchronization for WooCommerce <= 4.7.4 - Authenticated (Subscriber+) SQL Injection
WC Shop Sync – Square Payment Gateway and Product Synchronization for WooCommerce has a SQL injection issue. An attacker with the needed access can change a request and may read database data.
Updated Jul 15, 2026
FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution <= 3.1.7 - Unauthenticated Stored Cross-Site Scripting
FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
WPZOOM Portfolio Lite – Filterable Portfolio Plugin <= 1.4.29 - Unauthenticated Stored Cross-Site Scripting
WPZOOM Portfolio Lite – Filterable Portfolio Plugin has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
CVE-2026-58596 in Microsoft Edge Chromium
Microsoft Edge Chromium has an untrusted pointer dereference issue that can let an attacker gain elevated access over the network.
Updated Jul 15, 2026
CVE-2026-8085 in Rockwell Automation Arena Simulation
Arena Simulation has an out-of-bounds write issue in model.exe that can run code if a user opens a malicious file.
Updated Jul 15, 2026
