Search
3,173 CVEs
CVEs (3,173, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 3,173 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8297 | CRITICAL | 9.8 | 2026-07-17 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Ser… | |
| CVE-2026-12692 | CRITICAL | Patched | 9.8 | 2026-07-17 | Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0… |
| CVE-2026-60024 | CRITICAL | 9.8 | 2026-07-17 | Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow u… | |
| CVE-2026-51080 | CRITICAL | 9.8 | 2026-07-17 | libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability. | |
| CVE-2026-9810 | CRITICAL | Patched | 9.8 | 2026-07-17 | The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unaut… |
| CVE-2026-15982 | CRITICAL | 9.8 | 2026-07-17 | The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i… | |
| CVE-2026-14956 | CRITICAL | 9.8 | 2026-07-17 | The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds… | |
| CVE-2026-65605 | CRITICAL | 9.6 | 2026-07-23 | SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/… | |
| CVE-2026-65606 | CRITICAL | 9.6 | 2026-07-23 | SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an i… | |
| CVE-2026-65471 | CRITICAL | 9.6 | 2026-07-23 | Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions. | |
| CVE-2026-57784 | CRITICAL | 9.6 | 2026-07-23 | Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | |
| CVE-2026-16424 | CRITICAL | 9.6 | 2026-07-21 | Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbo… | |
| CVE-2026-62549 | CRITICAL | 9.6 | 2026-07-21 | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitab… | |
| CVE-2026-61097 | CRITICAL | 9.6 | 2026-07-21 | Vulnerability in the Oracle Banking Trade Finance Process Management product of Oracle Financial Services Applications (component: Common). Supported versions that are aff… | |
| CVE-2026-60773 | CRITICAL | 9.6 | 2026-07-21 | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easil… | |
| CVE-2026-60564 | CRITICAL | 9.6 | 2026-07-21 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.… | |
| CVE-2026-60540 | CRITICAL | 9.6 | 2026-07-21 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 an… | |
| CVE-2026-60239 | CRITICAL | 9.6 | 2026-07-21 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 an… | |
| CVE-2026-47413 | CRITICAL | 9.6 | 2026-07-21 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The… | |
| CVE-2026-47416 | CRITICAL | 9.6 | 2026-07-21 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /wo… | |
| CVE-2026-65007 | CRITICAL | Patched | 9.6 | 2026-07-21 | The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admi… |
| CVE-2026-15899 | CRITICAL | 9.6 | 2026-07-20 | Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (… | |
| CVE-2026-15900 | CRITICAL | 9.6 | 2026-07-20 | Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromi… | |
| CVE-2026-15901 | CRITICAL | 9.6 | 2026-07-20 | Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium secur… | |
| CVE-2026-15902 | CRITICAL | 9.6 | 2026-07-20 | Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium secu… |