Search
34,865 CVEs · Critical severity
CVEs (34,865, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 326–350 of 34,865 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-80589 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: block: stop the timeout timer when releasing a never added disk disk_release() undoes blk_mq_init_allo… | |
| CVE-2026-80587 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboptions Some MPTCP suboptions are mutually exclusive according… | |
| CVE-2026-80586 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: mptcp: options: reset DSS fields in case of unexpected size A remote peer could send a malformed DSS w… | |
| CVE-2026-80585 | CRITICAL | 9.4 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with SYN data Passive TCP Fast Open accepts a valid-cookie S… | |
| CVE-2026-80561 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: libceph: fix multiple unsafe decodes in decode_locker() decode_locker() in cls_lock_client.c contains … | |
| CVE-2026-80558 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: libceph: Avoid using invalid osd indices from primary_temp A corrupted osdmap received from a Ceph mon… | |
| CVE-2026-80557 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: libceph: fix OOB read in decode_watchers() via missing bounds check ceph_start_decoding() validates th… | |
| CVE-2026-80554 | CRITICAL | 9.3 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Limit the number of channel program segments The processing of channel programs, and th… | |
| CVE-2026-80551 | CRITICAL | 9.3 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Ensure first IDAW remains constant The first IDAW in a list does not need to be on a 2K… | |
| CVE-2026-80528 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: ceph: avoid fs reclaim while using current->journal_info handle_reply() stores a `ceph_mds_request` po… | |
| CVE-2026-80519 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: ovpn: finish crypto callback cleanup before peer release Crypto completion callbacks hold both key-slo… | |
| CVE-2026-8043 | CRITICAL | Patched | 9.6 | 2026-05-12 | External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a… |
| CVE-2026-80428 | CRITICAL | 9.8 | 2026-08-26 | ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code b… | |
| CVE-2026-8037 | CRITICAL | Patched | 9.6 | 2026-06-04 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster… |
| CVE-2026-80349 | CRITICAL | 9.8 | 2026-08-26 | TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header. app.js sets Koa's proxy option to true without naming which upstream p… | |
| CVE-2026-8034 | CRITICAL | Patched | 9.8 | 2026-05-07 | A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by ex… |
| CVE-2026-8025 | CRITICAL | 9.8 | 2026-06-09 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. CBS Platform allows SQL Injection. … | |
| CVE-2026-8024 | CRITICAL | 9.8 | 2026-06-18 | A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems. | |
| CVE-2026-80238 | CRITICAL | 9.3 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerabili… | |
| CVE-2026-80235 | CRITICAL | 9.8 | 2026-08-26 | EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, th… | |
| CVE-2026-80203 | CRITICAL | Patched | 9.8 | 2026-08-26 | The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-m… |
| CVE-2026-80138 | CRITICAL | 9.8 | 2026-08-25 | ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit… | |
| CVE-2026-80104 | CRITICAL | 9.8 | 2026-08-25 | DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src… | |
| CVE-2026-80098 | CRITICAL | 9.3 | 2026-09-03 | Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-79911 | CRITICAL | 10.0 | 2026-08-25 | A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi o… |