Search
34,865 CVEs · Critical severity
CVEs (34,865, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 34,865 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-78937 | CRITICAL | Patched | 9.6 | 2026-08-25 | Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code… |
| CVE-2026-78935 | CRITICAL | Patched | 9.6 | 2026-08-25 | Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbo… |
| CVE-2026-7891 | CRITICAL | 9.1 | 2026-05-07 | A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not adequately describe the special behavior of the System.… | |
| CVE-2026-78909 | CRITICAL | Patched | 9.6 | 2026-08-25 | Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a … |
| CVE-2026-78904 | CRITICAL | Patched | 9.6 | 2026-08-25 | Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.… |
| CVE-2026-78900 | CRITICAL | Patched | 9.6 | 2026-08-25 | Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted… |
| CVE-2026-7876 | CRITICAL | Patched | 9.1 | 2026-05-27 | IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage of this vulnerability t… |
| CVE-2026-78745 | CRITICAL | 9.8 | 2026-09-04 | An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via the Android Debug Bridge (ADB) daemon (adbd) | |
| CVE-2026-7874 | CRITICAL | Patched | 9.1 | 2026-06-30 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak and reversible key derivation mechanism for encrypt… |
| CVE-2026-7873 | CRITICAL | Patched | 9.9 | 2026-06-30 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete syst… |
| CVE-2026-7871 | CRITICAL | Patched | 9.8 | 2026-06-30 | IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system … |
| CVE-2026-78683 | CRITICAL | Patched | 9.6 | 2026-08-25 | NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.p… |
| CVE-2026-78676 | CRITICAL | Patched | 9.8 | 2026-08-25 | GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like co… |
| CVE-2026-78657 | CRITICAL | 9.8 | 2026-09-02 | The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_file… | |
| CVE-2026-78655 | CRITICAL | Patched | 9.1 | 2026-08-25 | Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts… |
| CVE-2026-78619 | CRITICAL | Patched | 9.8 | 2026-08-25 | Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers nume… |
| CVE-2026-7861 | CRITICAL | 9.8 | 2026-09-07 | Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (… | |
| CVE-2026-7858 | CRITICAL | 9.8 | 2026-06-01 | A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CA… | |
| CVE-2026-7854 | CRITICAL | 9.8 | 2026-05-05 | A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function url_rule_asp of the file /url_rule.asp of the compon… | |
| CVE-2026-7853 | CRITICAL | 9.8 | 2026-05-05 | A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulation … | |
| CVE-2026-7852 | CRITICAL | Patched | 9.8 | 2026-06-11 | Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclusion. This issue affects LimRAD NAC: before 5.5.7.3.9. |
| CVE-2026-7849 | CRITICAL | 9.8 | 2026-07-30 | Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently execu… | |
| CVE-2026-7840 | CRITICAL | Patched | 9.8 | 2026-07-01 | UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server. The functions wi_senderr() and wi_replyhdr() in repeater/web… |
| CVE-2026-7839 | CRITICAL | Patched | 9.1 | 2026-07-01 | UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repeater/webgui/settings.c:197, when settings2.txt is abs… |
| CVE-2026-78362 | CRITICAL | Patched | 9.8 | 2026-09-05 | The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be ser… |