Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

31,027 CVEs · Critical severity

CVEs (31,027, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 376–400 of 31,027 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-45787 CRITICAL Patched 9.1 2026-05-28 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt,…
CVE-2026-45772 CRITICAL Patched 9.8 2026-05-15 Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turborepo can be vulnerable to arbitrary code execution w…
CVE-2026-45758 CRITICAL Patched 9.6 2026-06-05 Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of `guardr…
CVE-2026-45750 CRITICAL Patched 9.0 2026-06-05 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/file_manager/ssh/resolveP…
CVE-2026-45748 CRITICAL Patched 9.8 2026-06-05 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /ssh/tunnel/connect` endpoint in Termix prior to ver…
CVE-2026-45746 CRITICAL Patched 9.0 2026-06-05 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the File Manager functionality in Term…
CVE-2026-45744 CRITICAL Patched 9.9 2026-06-05 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/file_manager/ssh/resolveP…
CVE-2026-45721 CRITICAL Patched 9.0 2026-05-26 Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that resolves to a directory without an index file, DirPage …
CVE-2026-45714 CRITICAL Patched 9.1 2026-05-13 CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (inc…
CVE-2026-45700 CRITICAL Patched 9.8 2026-05-29 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar d…
CVE-2026-45697 CRITICAL Patched 9.8 2026-05-29 Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Cust…
CVE-2026-4567 CRITICAL 9.8 2026-03-23 A vulnerability has been found in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file /cgi-bin/UploadCfg. The manipulation of the argument Fil…
CVE-2026-45663 CRITICAL 9.9 2026-05-29 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When…
CVE-2026-45661 CRITICAL 9.9 2026-05-29 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenti…
CVE-2026-45633 CRITICAL 9.9 2026-05-29 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSo…
CVE-2026-45632 CRITICAL 9.9 2026-05-29 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authen…
CVE-2026-45631 CRITICAL Patched 10.0 2026-05-29 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-secret-123456789") lets a…
CVE-2026-45630 CRITICAL 9.0 2026-05-29 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoin…
CVE-2026-45629 CRITICAL 9.9 2026-05-29 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows…
CVE-2026-45628 CRITICAL 9.6 2026-05-29 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template literals and executes them…
CVE-2026-45625 CRITICAL Patched 9.9 2026-05-29 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/custom…
CVE-2026-45570 CRITICAL Patched 9.6 2026-05-27 go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapp…
CVE-2026-45444 CRITICAL 10.0 2026-05-20 Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue affects Gift Cards For W…
CVE-2026-45434 CRITICAL Patched 9.8 2026-05-19 Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Us…
CVE-2026-45411 CRITICAL Patched 9.8 2026-05-13 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the gene…