Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

7,875 CVEs · Critical severity

CVEs (7,875, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 401–425 of 7,875 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-75357 CRITICAL 9.8 2026-08-27 An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili-bridge.js components.
CVE-2026-57499 CRITICAL Patched 9.1 2026-08-27 Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows an authentic…
CVE-2026-26897 CRITICAL 9.8 2026-08-27 An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain sensitive information and execute arbitrary code via…
CVE-2026-16279 CRITICAL 9.3 2026-08-27 An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gai…
CVE-2026-74233 CRITICAL Patched 9.8 2026-08-27 Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware …
CVE-2026-74232 CRITICAL Patched 9.8 2026-08-27 Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-762…
CVE-2026-78292 CRITICAL 9.8 2026-08-27 Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
CVE-2026-78288 CRITICAL 9.3 2026-08-27 Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
CVE-2026-78286 CRITICAL 9.8 2026-08-27 Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
CVE-2026-78274 CRITICAL 9.1 2026-08-27 Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
CVE-2026-78260 CRITICAL 9.3 2026-08-27 Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.
CVE-2026-59354 CRITICAL Patched 9.6 2026-08-27 In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint p&hellip;
CVE-2026-32566 CRITICAL 9.8 2026-08-27 Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
CVE-2026-32479 CRITICAL 9.3 2026-08-27 Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.
CVE-2026-77016 CRITICAL Patched 9.6 2026-08-27 The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored fil&hellip;
CVE-2026-59270 CRITICAL Patched 9.4 2026-08-27 Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network&hellip;
CVE-2026-47892 CRITICAL Patched 9.8 2026-08-27 A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framewor&hellip;
CVE-2026-47891 CRITICAL Patched 9.8 2026-08-27 A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 &hellip;
CVE-2026-47890 CRITICAL Patched 9.8 2026-08-27 Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Frame&hellip;
CVE-2026-47884 CRITICAL 9.8 2026-08-27 Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view nam&hellip;
CVE-2026-75340 CRITICAL 9.1 2026-08-26 The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF).
CVE-2026-75338 CRITICAL 9.8 2026-08-26 disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/&hellip;
CVE-2026-75336 CRITICAL 9.8 2026-08-26 Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json.
CVE-2026-75332 CRITICAL 9.1 2026-08-26 Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().
CVE-2026-75330 CRITICAL 9.8 2026-08-26 The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directl&hellip;