Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

34,969 CVEs · Critical severity

CVEs (34,969, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 326–350 of 34,969 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-0848 CRITICAL Patched 10.0 2026-03-05 NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Jav&hellip;
CVE-2026-29128 CRITICAL 10.0 2026-03-05 IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) that are owned by root bu&hellip;
CVE-2026-20131 CRITICAL 10.0 2026-03-04 A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute a&hellip;
CVE-2026-20079 CRITICAL 10.0 2026-03-04 A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and &hellip;
CVE-2026-28289 CRITICAL Patched 10.0 2026-03-03 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows a&hellip;
CVE-2026-24898 CRITICAL Patched 10.0 2026-03-03 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token disclosure vulnerability i&hellip;
CVE-2026-28409 CRITICAL Patched 10.0 2026-02-27 WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database &hellip;
CVE-2026-21718 CRITICAL Patched 10.0 2026-02-27 An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication requirement and achieve p&hellip;
CVE-2026-20127 CRITICAL Patched 10.0 2026-02-25 A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco&hellip;
CVE-2026-27597 CRITICAL Patched 10.0 2026-02-25 Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boundraries set by `@enclav&hellip;
CVE-2026-2776 CRITICAL Patched 10.0 2026-02-24 Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefo&hellip;
CVE-2026-2778 CRITICAL Patched 10.0 2026-02-24 Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, T&hellip;
CVE-2026-2768 CRITICAL Patched 10.0 2026-02-24 Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2760 CRITICAL Patched 10.0 2026-02-24 Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8&hellip;
CVE-2026-2761 CRITICAL Patched 10.0 2026-02-24 Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-23693 CRITICAL 10.0 2026-02-23 ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-js&hellip;
CVE-2026-27211 CRITICAL Patched 10.0 2026-02-21 Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. Versions 34.0 through 50.0 arevulnerable to arbitrary host file exfiltration (constrained by process priv&hellip;
CVE-2021-35402 CRITICAL Patched 10.0 2026-02-20 PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metacharacters in the ip parameter (for satellite_status).
CVE-2025-30411 CRITICAL 10.0 2026-02-20 Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938&hellip;
CVE-2025-30412 CRITICAL 10.0 2026-02-20 Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938&hellip;
CVE-2025-30416 CRITICAL 10.0 2026-02-20 Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, &hellip;
CVE-2026-22769 CRITICAL Patched 10.0 2026-02-17 Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remot&hellip;
CVE-2026-2577 CRITICAL 10.0 2026-02-16 The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not require authentication for inco&hellip;
CVE-2025-69770 CRITICAL 10.0 2026-02-13 A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via uploading a crafted zip file.
CVE-2026-26216 CRITICAL Patched 10.0 2026-02-12 Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python&hellip;