Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

13,088 CVEs

CVEs (13,088, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 276–300 of 13,088 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-12745 CRITICAL Patched 9.8 2026-09-08 A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
CVE-2026-71376 CRITICAL Patched 9.8 2026-09-08 OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 1…
CVE-2026-71377 CRITICAL Patched 9.8 2026-09-08 Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 be…
CVE-2026-62645 CRITICAL 9.8 2026-09-08 A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and &hellip;
CVE-2026-71374 CRITICAL Patched 9.8 2026-09-08 Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 1&hellip;
CVE-2026-58240 CRITICAL 9.8 2026-09-08 SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with&hellip;
CVE-2026-86543 CRITICAL Patched 9.8 2026-09-07 knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attack&hellip;
CVE-2026-86480 CRITICAL Patched 9.8 2026-09-07 In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges
CVE-2026-86478 CRITICAL Patched 9.8 2026-09-07 In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address
CVE-2026-7861 CRITICAL 9.8 2026-09-07 Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (&hellip;
CVE-2026-18922 CRITICAL 9.8 2026-09-07 A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can&hellip;
CVE-2026-76578 CRITICAL 9.8 2026-09-07 A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. A&hellip;
CVE-2026-86165 CRITICAL 9.8 2026-09-06 A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argu&hellip;
CVE-2026-75816 CRITICAL 9.8 2026-09-06 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due &hellip;
CVE-2026-16310 CRITICAL 9.8 2026-09-06 The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing vali&hellip;
CVE-2026-86189 CRITICAL 9.8 2026-09-05 WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a cal&hellip;
CVE-2026-86184 CRITICAL Patched 9.8 2026-09-05 Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user &hellip;
CVE-2026-10196 CRITICAL Patched 9.8 2026-09-05 The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc&hellip;
CVE-2026-86121 CRITICAL Patched 9.8 2026-09-05 Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthe&hellip;
CVE-2026-86124 CRITICAL 9.8 2026-09-05 AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. At&hellip;
CVE-2024-11080 CRITICAL 9.8 2026-09-05 The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in t&hellip;
CVE-2026-78362 CRITICAL Patched 9.8 2026-09-05 The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be ser&hellip;
CVE-2026-83627 CRITICAL 9.8 2026-09-05 The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21&hellip;
CVE-2026-13447 CRITICAL 9.8 2026-09-05 The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic sig&hellip;
CVE-2025-67066 CRITICAL 9.8 2026-09-04 SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path