Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

34,865 CVEs · Critical severity

CVEs (34,865, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 226–250 of 34,865 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-84121 CRITICAL Patched 9.6 2026-09-01 Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2,…
CVE-2026-84119 CRITICAL Patched 9.6 2026-09-01 Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.…
CVE-2026-8402 CRITICAL Patched 9.8 2026-06-30 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGU…
CVE-2026-8401 CRITICAL Patched 9.8 2026-05-12 Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.
CVE-2026-8398 CRITICAL 9.8 2026-05-15 A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimat…
CVE-2026-83772 CRITICAL 9.9 2026-09-01 A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-repor…
CVE-2026-8376 CRITICAL Patched 9.8 2026-05-26 Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_stu…
CVE-2026-83711 CRITICAL 10.0 2026-09-03 Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-8364 CRITICAL 9.8 2026-05-27 Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /re…
CVE-2026-8363 CRITICAL 9.8 2026-05-27 A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path starting with /resources:
CVE-2026-83627 CRITICAL 9.8 2026-09-05 The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21…
CVE-2026-8362 CRITICAL 9.8 2026-05-27 A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with /woshome
CVE-2026-83548 CRITICAL Patched 10.0 2026-09-01 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker c…
CVE-2026-83524 CRITICAL 9.9 2026-08-31 A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file …
CVE-2026-8307 CRITICAL 9.8 2026-07-08 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Injection. This issue affe…
CVE-2026-82971 CRITICAL 10.0 2026-08-31 A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This mani…
CVE-2026-82970 CRITICAL 10.0 2026-08-31 Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue…
CVE-2026-8297 CRITICAL 9.8 2026-07-17 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Ser…
CVE-2026-82954 CRITICAL 9.9 2026-08-31 A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts …
CVE-2026-82923 CRITICAL 9.8 2026-09-04 The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to…
CVE-2026-82874 CRITICAL 9.9 2026-08-31 ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allow…
CVE-2026-82872 CRITICAL 9.1 2026-08-31 ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspac…
CVE-2026-82870 CRITICAL 9.6 2026-08-31 ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in…
CVE-2026-82860 CRITICAL Patched 9.8 2026-08-31 @hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail. Attackers can craft admin-equiv…
CVE-2026-82859 CRITICAL 9.8 2026-08-31 hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM bounda…