Search
9,841 CVEs
CVEs (9,841, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 9,841 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63857 | CRITICAL | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit() The transmit loop in airo… | |
| CVE-2026-63825 | CRITICAL | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: gcov: use atomic counter updates to fix concurrent access crashes GCC's GCOV instrumentation can merge… | |
| CVE-2026-63808 | CRITICAL | Patched | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: exfat: fix potential use-after-free in exfat_find_dir_entry() In exfat_find_dir_entry(), the buffer_he… |
| CVE-2026-63800 | CRITICAL | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() When hitting the NFS_LAYOUT_RETURN branch in pnfs_upd… | |
| CVE-2026-53399 | CRITICAL | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure nfs4_alloc_stid() publishes the new stid into cl->cl_sta… | |
| CVE-2026-53398 | CRITICAL | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfsd4_decode_secinfo_no_name() currently initializes si… | |
| CVE-2026-53384 | CRITICAL | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails dw8250_probe() registers the 82… | |
| CVE-2026-47865 | CRITICAL | Patched | 9.8 | 2026-07-18 | VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the … |
| CVE-2026-52348 | CRITICAL | 9.8 | 2026-07-17 | cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java. | |
| CVE-2026-48062 | CRITICAL | Patched | 9.8 | 2026-07-17 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived gue… |
| CVE-2026-13446 | CRITICAL | Patched | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound c… |
| CVE-2026-8505 | CRITICAL | Patched | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The … |
| CVE-2026-63030 | CRITICAL | Patched | 9.8 | 2026-07-17 | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Inje… |
| CVE-2026-36669 | CRITICAL | 9.8 | 2026-07-17 | An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) … | |
| CVE-2026-9103 | CRITICAL | Patched | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The… |
| CVE-2026-9198 | CRITICAL | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code… | |
| CVE-2026-9202 | CRITICAL | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented … | |
| CVE-2026-8297 | CRITICAL | 9.8 | 2026-07-17 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Ser… | |
| CVE-2026-12692 | CRITICAL | Patched | 9.8 | 2026-07-17 | Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0… |
| CVE-2026-60024 | CRITICAL | 9.8 | 2026-07-17 | Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow u… | |
| CVE-2026-51080 | CRITICAL | 9.8 | 2026-07-17 | libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability. | |
| CVE-2026-9810 | CRITICAL | Patched | 9.8 | 2026-07-17 | The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unaut… |
| CVE-2026-15982 | CRITICAL | 9.8 | 2026-07-17 | The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i… | |
| CVE-2026-14956 | CRITICAL | 9.8 | 2026-07-17 | The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds… | |
| CVE-2026-53412 | CRITICAL | 9.8 | 2026-07-16 | Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an … |