Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,217 CVEs

CVEs (30,217, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 426–450 of 30,217 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-70615 CRITICAL 9.9 2026-08-05 boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lin…
CVE-2026-20303 CRITICAL 9.9 2026-08-05 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security …
CVE-2026-20304 CRITICAL 9.9 2026-08-05 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security …
CVE-2026-9193 CRITICAL Patched 9.9 2026-08-05 An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privi…
CVE-2026-7329 CRITICAL Patched 9.9 2026-08-05 An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authentic…
CVE-2026-8709 CRITICAL Patched 9.9 2026-08-05 An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user w…
CVE-2026-71268 CRITICAL 9.9 2026-08-05 OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.st) program files and writes the referenced content t…
CVE-2026-48326 CRITICAL Patched 9.9 2026-08-03 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbit…
CVE-2026-67330 CRITICAL Patched 9.9 2026-08-01 @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token&hellip;
CVE-2026-52855 CRITICAL Patched 9.9 2026-07-31 Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file tem&hellip;
CVE-2026-17566 CRITICAL Patched 9.9 2026-07-31 pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to&hellip;
CVE-2026-12946 CRITICAL Patched 9.9 2026-07-30 IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.
CVE-2026-13435 CRITICAL Patched 9.9 2026-07-30 IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.
CVE-2026-58046 CRITICAL 9.9 2026-07-30 Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database,&hellip;
CVE-2026-54680 CRITICAL Patched 9.9 2026-07-29 Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logg&hellip;
CVE-2026-63232 CRITICAL 9.9 2026-07-29 A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control d&hellip;
CVE-2026-63233 CRITICAL 9.9 2026-07-29 A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control &hellip;
CVE-2026-63234 CRITICAL 9.9 2026-07-29 A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control dat&hellip;
CVE-2026-63227 CRITICAL 9.9 2026-07-29 An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly ac&hellip;
CVE-2026-48030 CRITICAL Patched 9.9 2026-07-27 Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action h&hellip;
CVE-2026-54120 CRITICAL 9.9 2026-07-24 Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
CVE-2026-50517 CRITICAL 9.9 2026-07-24 Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
CVE-2026-63732 CRITICAL Patched 9.9 2026-07-23 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL&hellip;
CVE-2024-58354 CRITICAL 9.9 2026-07-23 cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_req&hellip;
CVE-2026-47724 CRITICAL 9.9 2026-07-23 nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trusts the bearer token alon&hellip;