Search
34,854 CVEs · Critical severity
CVEs (34,854, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 34,854 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-32566 | CRITICAL | 9.8 | 2026-08-27 | Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. | |
| CVE-2026-32479 | CRITICAL | 9.3 | 2026-08-27 | Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions. | |
| CVE-2026-77016 | CRITICAL | Patched | 9.6 | 2026-08-27 | The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored fil… |
| CVE-2026-59270 | CRITICAL | Patched | 9.4 | 2026-08-27 | Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network… |
| CVE-2026-47892 | CRITICAL | Patched | 9.8 | 2026-08-27 | A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framewor… |
| CVE-2026-47891 | CRITICAL | Patched | 9.8 | 2026-08-27 | A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 … |
| CVE-2026-47890 | CRITICAL | Patched | 9.8 | 2026-08-27 | Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Frame… |
| CVE-2026-47884 | CRITICAL | 9.8 | 2026-08-27 | Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view nam… | |
| CVE-2026-75340 | CRITICAL | 9.1 | 2026-08-26 | The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF). | |
| CVE-2026-75338 | CRITICAL | 9.8 | 2026-08-26 | disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/… | |
| CVE-2026-75336 | CRITICAL | 9.8 | 2026-08-26 | Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json. | |
| CVE-2026-75332 | CRITICAL | 9.1 | 2026-08-26 | Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download(). | |
| CVE-2026-75330 | CRITICAL | 9.8 | 2026-08-26 | The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directl… | |
| CVE-2026-75329 | CRITICAL | 9.8 | 2026-08-26 | The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configurat… | |
| CVE-2026-75414 | CRITICAL | 9.8 | 2026-08-26 | In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability. | |
| CVE-2026-75411 | CRITICAL | 9.8 | 2026-08-26 | JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class e… | |
| CVE-2026-52103 | CRITICAL | 9.8 | 2026-08-26 | A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands… | |
| CVE-2025-51679 | CRITICAL | 9.1 | 2026-08-26 | An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected behavior. | |
| CVE-2026-75334 | CRITICAL | 9.8 | 2026-08-26 | The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql parameter is stored in the t_report_sql_resource table t… | |
| CVE-2026-75327 | CRITICAL | 9.8 | 2026-08-26 | In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability: | |
| CVE-2026-68000 | CRITICAL | 9.8 | 2026-08-26 | The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directly concatenated into the LIMIT clause of SQL through … | |
| CVE-2026-60004 | CRITICAL | Patched | 9.8 | 2026-08-26 | Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. |
| CVE-2026-26448 | CRITICAL | 9.8 | 2026-08-26 | Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection, and subsequently another client (or a later connect… | |
| CVE-2025-70293 | CRITICAL | Patched | 9.8 | 2026-08-26 | An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allo… |
| CVE-2025-70290 | CRITICAL | Patched | 9.8 | 2026-08-26 | An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The i… |