Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

32,636 CVEs · Critical severity

CVEs (32,636, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 376–400 of 32,636 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-62414 CRITICAL 9.1 2026-07-20 Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply access control to fronten&hellip;
CVE-2026-39878 CRITICAL Patched 9.3 2026-07-20 Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execu&hellip;
CVE-2026-54051 CRITICAL Patched 9.9 2026-07-20 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAll&hellip;
CVE-2026-41252 CRITICAL Patched 9.8 2026-07-20 xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mod&hellip;
CVE-2026-35048 CRITICAL 9.8 2026-07-20 The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper&hellip;
CVE-2026-51027 CRITICAL 9.9 2026-07-20 An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.
CVE-2026-46412 CRITICAL 10.0 2026-07-20 @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an att&hellip;
CVE-2026-35198 CRITICAL 9.0 2026-07-20 HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team memb&hellip;
CVE-2026-63071 CRITICAL Patched 9.8 2026-07-20 Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy c&hellip;
CVE-2026-57308 CRITICAL Patched 9.8 2026-07-20 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achie&hellip;
CVE-2026-62183 CRITICAL Patched 9.8 2026-07-20 Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is config&hellip;
CVE-2026-53421 CRITICAL Patched 9.8 2026-07-20 Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the con&hellip;
CVE-2026-53405 CRITICAL Patched 9.8 2026-07-20 Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via t&hellip;
CVE-2026-12701 CRITICAL 9.0 2026-07-20 A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directo&hellip;
CVE-2026-64620 CRITICAL Patched 9.8 2026-07-20 FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponen&hellip;
CVE-2026-16242 CRITICAL 9.4 2026-07-20 A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without toke&hellip;
CVE-2026-16235 CRITICAL 9.8 2026-07-20 Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitabl&hellip;
CVE-2026-13147 CRITICAL Patched 9.1 2026-07-20 The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue &hellip;
CVE-2026-44359 CRITICAL 10.0 2026-07-20 Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_req&hellip;
CVE-2026-64160 CRITICAL 9.8 2026-07-19 In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential for tearing in ->remote_i_size and ->zero_point Fix potential tearing in using ->&hellip;
CVE-2026-64162 CRITICAL 9.8 2026-07-19 In the Linux kernel, the following vulnerability has been resolved: idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init() In idpf_ptp_init(), read_dev_clk_lock is &hellip;
CVE-2026-64142 CRITICAL 9.8 2026-07-19 In the Linux kernel, the following vulnerability has been resolved: ksmbd: close durable scavenger races against m_fp_list lookups ksmbd_durable_scavenger() has two relat&hellip;
CVE-2026-64150 CRITICAL 9.8 2026-07-19 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: release local_lock before re-enabling softirqs Quoting sashiko: In the error pa&hellip;
CVE-2026-64132 CRITICAL 9.8 2026-07-19 In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: refresh hdr pointer before ioam6_event() Reported by Sashiko: In ipv6_hop_ioam(), the hdr&hellip;
CVE-2026-64136 CRITICAL 9.8 2026-07-19 In the Linux kernel, the following vulnerability has been resolved: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() Commit 96c4af418586 ("ci&hellip;