Security Risk Severity

High Security Risks — Page 13

Published vulnerability pages grouped by high severity. Use this page to review risks that need similar prioritization.

872 published high risks

High severity

Showing 433–468 of 872 published risks.

Clear
highEPSS 0.001

CVE-2026-59836 in FortiClient EMS

A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>

CVE-2026-59836network-securityinformation-disclosurecryptography

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-54433 in Roundcube Webmail

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or...

CVE-2026-54433web-applicationxss

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-45074 in Symfony Security HTTP

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter from Request::getSchemeAndHttpHost(), which reflects an attacker-controlled...

CVE-2026-45074phpweb-applicationauthentication-bypass

Updated Jul 15, 2026

highEPSS 0.006

CVE-2026-45077 in Symfony Monolog Bridge

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default and...

CVE-2026-45077phpweb-applicationremote-code-executionunsafe-deserialization

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-45756 in Symfony JSON Path

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until 7.4.12 and 8.0.12, the JsonPath component compiles attacker-controlled match() and search() filter patterns directly into preg_match()...

CVE-2026-45756phpweb-applicationinput-validationdenial-of-service

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-55021 in Microsoft SharePoint Server

Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.

CVE-2026-55021windowsmicrosoftweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.006

CVE-2026-55034 in Microsoft SharePoint Server

Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.

CVE-2026-55034windowsmicrosoftweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-55947 in Microsoft Excel / Microsoft 365 Apps

Microsoft Excel has a memory corruption issue that can let an attacker run code when a user opens a malicious file.

CVE-2026-55947windowsmicrosoftremote-code-executionmemory-corruption

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-55949 in Microsoft Excel / Microsoft 365 Apps

Microsoft Excel has an uninitialized resource issue that can let an attacker run code when a user opens a malicious file.

CVE-2026-55949windowsmicrosoftremote-code-executionmemory-corruption

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-56156 in Microsoft Excel / Microsoft 365 Apps

Microsoft Excel has a memory corruption issue that can let an attacker run code when a user opens a malicious file.

CVE-2026-56156windowsmicrosoftremote-code-executionmemory-corruption

Updated Jul 15, 2026

highEPSS 0.008

CVE-2026-58277 in Microsoft SharePoint Server

Microsoft SharePoint Server has an authorization issue that can let an authorized attacker gain higher privileges over the network.

CVE-2026-58277windowsmicrosoftweb-applicationauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-45069 in Symfony Security HTTP

Symfony Security HTTP can accept OIDC tokens that miss required audience, issuer, or expiry claims.

CVE-2026-45069phpweb-applicationauthentication-bypass

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-45075 in Symfony Security HTTP

Symfony Security HTTP can let HEAD requests bypass checks that only allow GET requests.

CVE-2026-45075phpweb-applicationauthorization-bypasscsrf

Updated Jul 15, 2026

highEPSS 0.006

CVE-2026-45133 in Symfony YAML

Symfony YAML can crash a worker when it parses very deeply nested YAML input.

CVE-2026-45133phpweb-applicationinput-validationdenial-of-service

Updated Jul 15, 2026

highEPSS 0.008

CVE-2026-45304 in Symfony YAML

Symfony YAML can use too much memory when crafted aliases expand recursively.

CVE-2026-45304phpweb-applicationinput-validationdenial-of-service

Updated Jul 15, 2026

highEPSS 0.007

CVE-2026-45305 in Symfony YAML

Symfony YAML can hang on crafted YAML because of slow regex backtracking.

CVE-2026-45305phpweb-applicationinput-validationdenial-of-service

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-45071 in Symfony DomCrawler

Symfony DomCrawler can read local files when it parses attacker-controlled XML content.

CVE-2026-45071phpweb-applicationinput-validationinformation-disclosure

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-47984 in Adobe Commerce

Adobe Commerce has an authorization issue that can let an attacker gain unauthorized read and write access.

CVE-2026-47984phpweb-applicationauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-47988 in Adobe Commerce

Adobe Commerce has an authorization issue that can let an attacker gain unauthorized read and write access.

CVE-2026-47988phpweb-applicationauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.196

CVE-2026-47992 in Adobe Commerce

Adobe Commerce has a SQL injection issue that can lead to code execution for a high-privilege attacker.

CVE-2026-47992phpweb-applicationremote-code-executionsql-injection

Updated Jul 15, 2026

highEPSS 0.009

CVE-2026-47994 in Adobe Commerce

Adobe Commerce has a stored XSS issue that can help an attacker gain more access through a victim browser.

CVE-2026-47994phpbrowserweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.007

CVE-2026-47995 in Adobe Commerce

Adobe Commerce has a stored XSS issue that can help an attacker gain more access through a victim browser.

CVE-2026-47995phpbrowserweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.185

CVE-2026-47996 in Adobe Commerce

Adobe Commerce has an authorization issue that can let a high-privilege attacker bypass rules and read data.

CVE-2026-47996phpweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-48489 in Symfony Security HTTP

Symfony Security HTTP can let a failed login request reach protected GET routes when failure forwarding is enabled.

CVE-2026-48489phpweb-applicationauthentication-bypassauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.002

Unlimited Elements For Elementor <= 2.0.12 - Unauthenticated Stored Cross-Site Scripting

Unlimited Elements For Elementor has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57718wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.002

Database for Contact Form 7, WPforms, Elementor forms <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting

Database for Contact Form 7, WPforms, Elementor forms has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57708wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.002

Document Gallery <= 5.1.0 - Unauthenticated Stored Cross-Site Scripting

Document Gallery has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57695wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.002

NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting

NEX-Forms – Ultimate Forms Plugin for WordPress has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57668wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.002

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.6 - Unauthenticated Stored Cross-Site Scripting

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57706wordpresswoocommercebrowserxss

Updated Jul 15, 2026

highEPSS 0.001

FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.15.0.8 - Unauthenticated Stored Cross-Site Scripting

FunnelKit – Funnel Builder for WooCommerce Checkout has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57816wordpresswoocommercebrowserxss

Updated Jul 15, 2026

highEPSS 0.001

ICS Calendar <= 12.1.1 - Unauthenticated Stored Cross-Site Scripting

ICS Calendar has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-59516wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.002

WC Shop Sync – Square Payment Gateway and Product Synchronization for WooCommerce <= 4.7.4 - Authenticated (Subscriber+) SQL Injection

WC Shop Sync – Square Payment Gateway and Product Synchronization for WooCommerce has a SQL injection issue. An attacker with the needed access can change a request and may read database data.

CVE-2026-57810wordpresswoocommercenetwork-securitysql-injection

Updated Jul 15, 2026

highEPSS 0.002

FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution <= 3.1.7 - Unauthenticated Stored Cross-Site Scripting

FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57715wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.002

WPZOOM Portfolio Lite – Filterable Portfolio Plugin <= 1.4.29 - Unauthenticated Stored Cross-Site Scripting

WPZOOM Portfolio Lite – Filterable Portfolio Plugin has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57712wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-58596 in Microsoft Edge Chromium

Microsoft Edge Chromium has an untrusted pointer dereference issue that can let an attacker gain elevated access over the network.

CVE-2026-58596browserlinuxwindowsmicrosoft

Updated Jul 15, 2026

highEPSS 0.001

CVE-2026-8085 in Rockwell Automation Arena Simulation

Arena Simulation has an out-of-bounds write issue in model.exe that can run code if a user opens a malicious file.

CVE-2026-8085windowsindustrial-controlremote-code-executionmemory-corruption

Updated Jul 15, 2026