Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

34,854 CVEs · Critical severity

CVEs (34,854, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 401–425 of 34,854 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-32566 CRITICAL 9.8 2026-08-27 Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
CVE-2026-32479 CRITICAL 9.3 2026-08-27 Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.
CVE-2026-77016 CRITICAL Patched 9.6 2026-08-27 The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored fil&hellip;
CVE-2026-59270 CRITICAL Patched 9.4 2026-08-27 Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network&hellip;
CVE-2026-47892 CRITICAL Patched 9.8 2026-08-27 A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framewor&hellip;
CVE-2026-47891 CRITICAL Patched 9.8 2026-08-27 A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 &hellip;
CVE-2026-47890 CRITICAL Patched 9.8 2026-08-27 Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Frame&hellip;
CVE-2026-47884 CRITICAL 9.8 2026-08-27 Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view nam&hellip;
CVE-2026-75340 CRITICAL 9.1 2026-08-26 The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF).
CVE-2026-75338 CRITICAL 9.8 2026-08-26 disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/&hellip;
CVE-2026-75336 CRITICAL 9.8 2026-08-26 Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json.
CVE-2026-75332 CRITICAL 9.1 2026-08-26 Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().
CVE-2026-75330 CRITICAL 9.8 2026-08-26 The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directl&hellip;
CVE-2026-75329 CRITICAL 9.8 2026-08-26 The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configurat&hellip;
CVE-2026-75414 CRITICAL 9.8 2026-08-26 In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability.
CVE-2026-75411 CRITICAL 9.8 2026-08-26 JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class e&hellip;
CVE-2026-52103 CRITICAL 9.8 2026-08-26 A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands&hellip;
CVE-2025-51679 CRITICAL 9.1 2026-08-26 An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected behavior.
CVE-2026-75334 CRITICAL 9.8 2026-08-26 The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql parameter is stored in the t_report_sql_resource table t&hellip;
CVE-2026-75327 CRITICAL 9.8 2026-08-26 In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability:
CVE-2026-68000 CRITICAL 9.8 2026-08-26 The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directly concatenated into the LIMIT clause of SQL through &hellip;
CVE-2026-60004 CRITICAL Patched 9.8 2026-08-26 Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
CVE-2026-26448 CRITICAL 9.8 2026-08-26 Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection, and subsequently another client (or a later connect&hellip;
CVE-2025-70293 CRITICAL Patched 9.8 2026-08-26 An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allo&hellip;
CVE-2025-70290 CRITICAL Patched 9.8 2026-08-26 An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The i&hellip;