Search
32,636 CVEs · Critical severity
CVEs (32,636, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 32,636 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-16349 | CRITICAL | Patched | 9.8 | 2026-07-21 | Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunde… |
| CVE-2026-65008 | CRITICAL | Patched | 9.8 | 2026-07-21 | Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::me… |
| CVE-2026-65007 | CRITICAL | Patched | 9.6 | 2026-07-21 | The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admi… |
| CVE-2026-1617 | CRITICAL | Patched | 9.8 | 2026-07-21 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama allows S… |
| CVE-2026-64606 | CRITICAL | Patched | 9.8 | 2026-07-21 | Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is aff… |
| CVE-2026-64609 | CRITICAL | Patched | 9.1 | 2026-07-21 | Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying… |
| CVE-2026-64608 | CRITICAL | Patched | 9.8 | 2026-07-21 | Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly va… |
| CVE-2026-62415 | CRITICAL | 9.1 | 2026-07-21 | Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow u… | |
| CVE-2026-13439 | CRITICAL | 9.8 | 2026-07-21 | The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 Th… | |
| CVE-2026-15902 | CRITICAL | 9.6 | 2026-07-20 | Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium secu… | |
| CVE-2026-15901 | CRITICAL | 9.6 | 2026-07-20 | Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium secur… | |
| CVE-2026-15900 | CRITICAL | 9.6 | 2026-07-20 | Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromi… | |
| CVE-2026-15899 | CRITICAL | 9.6 | 2026-07-20 | Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (… | |
| CVE-2026-64625 | CRITICAL | Patched | 9.8 | 2026-07-20 | AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() a… |
| CVE-2026-52656 | CRITICAL | 9.8 | 2026-07-20 | An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary code via a crafted FEX file | |
| CVE-2024-51315 | CRITICAL | 9.8 | 2026-07-20 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName | |
| CVE-2024-51314 | CRITICAL | 9.8 | 2026-07-20 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg. | |
| CVE-2024-51312 | CRITICAL | 9.8 | 2026-07-20 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg. | |
| CVE-2026-53595 | CRITICAL | 9.4 | 2026-07-20 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` … | |
| CVE-2024-51313 | CRITICAL | 9.8 | 2026-07-20 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg. | |
| CVE-2024-51311 | CRITICAL | 9.8 | 2026-07-20 | The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList. | |
| CVE-2026-63767 | CRITICAL | Patched | 9.8 | 2026-07-20 | ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary com… |
| CVE-2026-63766 | CRITICAL | 9.8 | 2026-07-20 | GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio tex… | |
| CVE-2026-44231 | CRITICAL | Patched | 9.1 | 2026-07-20 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and pri… |
| CVE-2026-64193 | CRITICAL | 9.8 | 2026-07-20 | Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field… |