Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

32,636 CVEs · Critical severity

CVEs (32,636, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 351–375 of 32,636 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-16349 CRITICAL Patched 9.8 2026-07-21 Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunde…
CVE-2026-65008 CRITICAL Patched 9.8 2026-07-21 Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::me…
CVE-2026-65007 CRITICAL Patched 9.6 2026-07-21 The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admi…
CVE-2026-1617 CRITICAL Patched 9.8 2026-07-21 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama allows S…
CVE-2026-64606 CRITICAL Patched 9.8 2026-07-21 Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is aff…
CVE-2026-64609 CRITICAL Patched 9.1 2026-07-21 Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying…
CVE-2026-64608 CRITICAL Patched 9.8 2026-07-21 Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly va…
CVE-2026-62415 CRITICAL 9.1 2026-07-21 Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow u&hellip;
CVE-2026-13439 CRITICAL 9.8 2026-07-21 The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 Th&hellip;
CVE-2026-15902 CRITICAL 9.6 2026-07-20 Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium secu&hellip;
CVE-2026-15901 CRITICAL 9.6 2026-07-20 Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium secur&hellip;
CVE-2026-15900 CRITICAL 9.6 2026-07-20 Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromi&hellip;
CVE-2026-15899 CRITICAL 9.6 2026-07-20 Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (&hellip;
CVE-2026-64625 CRITICAL Patched 9.8 2026-07-20 AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() a&hellip;
CVE-2026-52656 CRITICAL 9.8 2026-07-20 An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary code via a crafted FEX file
CVE-2024-51315 CRITICAL 9.8 2026-07-20 The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName
CVE-2024-51314 CRITICAL 9.8 2026-07-20 The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg.
CVE-2024-51312 CRITICAL 9.8 2026-07-20 The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg.
CVE-2026-53595 CRITICAL 9.4 2026-07-20 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` &hellip;
CVE-2024-51313 CRITICAL 9.8 2026-07-20 The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg.
CVE-2024-51311 CRITICAL 9.8 2026-07-20 The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList.
CVE-2026-63767 CRITICAL Patched 9.8 2026-07-20 ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary com&hellip;
CVE-2026-63766 CRITICAL 9.8 2026-07-20 GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio tex&hellip;
CVE-2026-44231 CRITICAL Patched 9.1 2026-07-20 RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and pri&hellip;
CVE-2026-64193 CRITICAL 9.8 2026-07-20 Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field&hellip;