Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

34,865 CVEs · Critical severity

CVEs (34,865, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 401–425 of 34,865 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-78937 CRITICAL Patched 9.6 2026-08-25 Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code…
CVE-2026-78935 CRITICAL Patched 9.6 2026-08-25 Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbo…
CVE-2026-7891 CRITICAL 9.1 2026-05-07 A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not adequately describe the special behavior of the System.…
CVE-2026-78909 CRITICAL Patched 9.6 2026-08-25 Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a …
CVE-2026-78904 CRITICAL Patched 9.6 2026-08-25 Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.…
CVE-2026-78900 CRITICAL Patched 9.6 2026-08-25 Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted…
CVE-2026-7876 CRITICAL Patched 9.1 2026-05-27 IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage of this vulnerability t…
CVE-2026-78745 CRITICAL 9.8 2026-09-04 An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via the Android Debug Bridge (ADB) daemon (adbd)
CVE-2026-7874 CRITICAL Patched 9.1 2026-06-30 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak and reversible key derivation mechanism for encrypt…
CVE-2026-7873 CRITICAL Patched 9.9 2026-06-30 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete syst…
CVE-2026-7871 CRITICAL Patched 9.8 2026-06-30 IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system …
CVE-2026-78683 CRITICAL Patched 9.6 2026-08-25 NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.p&hellip;
CVE-2026-78676 CRITICAL Patched 9.8 2026-08-25 GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like co&hellip;
CVE-2026-78657 CRITICAL 9.8 2026-09-02 The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_file&hellip;
CVE-2026-78655 CRITICAL Patched 9.1 2026-08-25 Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts&hellip;
CVE-2026-78619 CRITICAL Patched 9.8 2026-08-25 Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers nume&hellip;
CVE-2026-7861 CRITICAL 9.8 2026-09-07 Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (&hellip;
CVE-2026-7858 CRITICAL 9.8 2026-06-01 A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CA&hellip;
CVE-2026-7854 CRITICAL 9.8 2026-05-05 A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function url_rule_asp of the file /url_rule.asp of the compon&hellip;
CVE-2026-7853 CRITICAL 9.8 2026-05-05 A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulation &hellip;
CVE-2026-7852 CRITICAL Patched 9.8 2026-06-11 Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclusion. This issue affects LimRAD NAC: before 5.5.7.3.9.
CVE-2026-7849 CRITICAL 9.8 2026-07-30 Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently execu&hellip;
CVE-2026-7840 CRITICAL Patched 9.8 2026-07-01 UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server. The functions wi_senderr() and wi_replyhdr() in repeater/web&hellip;
CVE-2026-7839 CRITICAL Patched 9.1 2026-07-01 UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repeater/webgui/settings.c:197, when settings2.txt is abs&hellip;
CVE-2026-78362 CRITICAL Patched 9.8 2026-09-05 The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be ser&hellip;