Search
34,865 CVEs · Critical severity
CVEs (34,865, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 276–300 of 34,865 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-82277 | CRITICAL | 9.8 | 2026-08-28 | Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers … | |
| CVE-2026-82266 | CRITICAL | 9.8 | 2026-08-28 | Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can … | |
| CVE-2026-82244 | CRITICAL | Patched | 9.1 | 2026-08-28 | Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploadin… |
| CVE-2026-82226 | CRITICAL | 9.8 | 2026-08-31 | Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions. | |
| CVE-2026-82222 | CRITICAL | 10.0 | 2026-08-28 | Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1. | |
| CVE-2026-82082 | CRITICAL | 9.8 | 2026-08-28 | NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server. | |
| CVE-2026-82078 | CRITICAL | Patched | 9.1 | 2026-08-28 | An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver class… |
| CVE-2026-8206 | CRITICAL | 9.8 | 2026-06-02 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0… | |
| CVE-2026-81939 | CRITICAL | 9.1 | 2026-09-04 | A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outsid… | |
| CVE-2026-8181 | CRITICAL | 9.8 | 2026-05-14 | The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to … | |
| CVE-2026-81780 | CRITICAL | 10.0 | 2026-08-31 | Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. | |
| CVE-2026-81779 | CRITICAL | 10.0 | 2026-08-31 | Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0… | |
| CVE-2026-81763 | CRITICAL | 9.3 | 2026-08-31 | Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions. | |
| CVE-2026-81756 | CRITICAL | 9.3 | 2026-08-31 | Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. | |
| CVE-2026-8175 | CRITICAL | Patched | 9.8 | 2026-05-27 | IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Tr… |
| CVE-2026-81735 | CRITICAL | 10.0 | 2026-08-27 | startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound th… | |
| CVE-2026-81707 | CRITICAL | Patched | 9.8 | 2026-08-27 | openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint… |
| CVE-2026-81702 | CRITICAL | Patched | 9.8 | 2026-08-27 | openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identi… |
| CVE-2026-81701 | CRITICAL | Patched | 9.8 | 2026-08-27 | openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirect… |
| CVE-2026-81700 | CRITICAL | Patched | 9.8 | 2026-08-27 | openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VA… |
| CVE-2026-81578 | CRITICAL | Patched | 9.8 | 2026-08-28 | An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests t… |
| CVE-2026-8153 | CRITICAL | 9.8 | 2026-05-08 | OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthenticated attacker to craft commands that will execut… | |
| CVE-2026-81294 | CRITICAL | 9.8 | 2026-09-02 | Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions. | |
| CVE-2026-81293 | CRITICAL | 9.3 | 2026-08-31 | Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions. | |
| CVE-2026-81286 | CRITICAL | 9.3 | 2026-09-02 | Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions. |