Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

34,865 CVEs · Critical severity

CVEs (34,865, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 301–325 of 34,865 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-15980 CRITICAL 9.8 2026-08-30 The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_li…
CVE-2026-15369 CRITICAL 9.8 2026-08-29 The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the p…
CVE-2026-82460 CRITICAL Patched 9.8 2026-08-29 Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization…
CVE-2026-82456 CRITICAL 10.0 2026-08-29 argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Atta…
CVE-2026-82454 CRITICAL 9.1 2026-08-29 The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extrac…
CVE-2026-82452 CRITICAL 9.8 2026-08-29 rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures.…
CVE-2026-82448 CRITICAL 9.8 2026-08-29 Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. At…
CVE-2026-14494 CRITICAL 9.8 2026-08-29 The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is…
CVE-2026-80725 CRITICAL 9.8 2026-08-29 In the Linux kernel, the following vulnerability has been resolved: net: gro: properly validate BIG TCP aggregation criteria When GRO attempts to aggregate packets beyond…
CVE-2026-77012 CRITICAL 9.3 2026-08-29 The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, …
CVE-2026-16947 CRITICAL 9.1 2026-08-29 The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification r…
CVE-2026-16259 CRITICAL 9.8 2026-08-29 The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester,…
CVE-2026-10522 CRITICAL 9.8 2026-08-29 The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend registration process, allowing unauthenticated attac…
CVE-2026-51663 CRITICAL 9.8 2026-08-28 Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger wireless scans and retrieve AP-cl…
CVE-2026-51661 CRITICAL 9.1 2026-08-28 Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain port-forwarding rules via sendi…
CVE-2026-3627 CRITICAL Patched 9.1 2026-08-28 IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, …
CVE-2026-19295 CRITICAL Patched 9.9 2026-08-28 IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted …
CVE-2026-19286 CRITICAL Patched 9.8 2026-08-28 IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.
CVE-2026-18527 CRITICAL 9.9 2026-08-28 IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI compon…
CVE-2026-82329 CRITICAL Patched 9.8 2026-08-28 JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative …
CVE-2026-82277 CRITICAL 9.8 2026-08-28 Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers …
CVE-2026-82266 CRITICAL 9.8 2026-08-28 Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can …
CVE-2026-55634 CRITICAL Patched 9.9 2026-08-28 Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/def…
CVE-2026-55565 CRITICAL Patched 9.9 2026-08-28 Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExp…
CVE-2026-55559 CRITICAL Patched 9.8 2026-08-28 Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through …