Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 30,217 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-70615 | CRITICAL | 9.9 | 2026-08-05 | boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lin… | |
| CVE-2026-20303 | CRITICAL | 9.9 | 2026-08-05 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security … | |
| CVE-2026-20304 | CRITICAL | 9.9 | 2026-08-05 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security … | |
| CVE-2026-9193 | CRITICAL | Patched | 9.9 | 2026-08-05 | An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privi… |
| CVE-2026-7329 | CRITICAL | Patched | 9.9 | 2026-08-05 | An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authentic… |
| CVE-2026-8709 | CRITICAL | Patched | 9.9 | 2026-08-05 | An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user w… |
| CVE-2026-71268 | CRITICAL | 9.9 | 2026-08-05 | OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.st) program files and writes the referenced content t… | |
| CVE-2026-48326 | CRITICAL | Patched | 9.9 | 2026-08-03 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbit… |
| CVE-2026-67330 | CRITICAL | Patched | 9.9 | 2026-08-01 | @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token… |
| CVE-2026-52855 | CRITICAL | Patched | 9.9 | 2026-07-31 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file tem… |
| CVE-2026-17566 | CRITICAL | Patched | 9.9 | 2026-07-31 | pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to… |
| CVE-2026-12946 | CRITICAL | Patched | 9.9 | 2026-07-30 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code. |
| CVE-2026-13435 | CRITICAL | Patched | 9.9 | 2026-07-30 | IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation. |
| CVE-2026-58046 | CRITICAL | 9.9 | 2026-07-30 | Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database,… | |
| CVE-2026-54680 | CRITICAL | Patched | 9.9 | 2026-07-29 | Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logg… |
| CVE-2026-63232 | CRITICAL | 9.9 | 2026-07-29 | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control d… | |
| CVE-2026-63233 | CRITICAL | 9.9 | 2026-07-29 | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control … | |
| CVE-2026-63234 | CRITICAL | 9.9 | 2026-07-29 | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control dat… | |
| CVE-2026-63227 | CRITICAL | 9.9 | 2026-07-29 | An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly ac… | |
| CVE-2026-48030 | CRITICAL | Patched | 9.9 | 2026-07-27 | Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action h… |
| CVE-2026-54120 | CRITICAL | 9.9 | 2026-07-24 | Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. | |
| CVE-2026-50517 | CRITICAL | 9.9 | 2026-07-24 | Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. | |
| CVE-2026-63732 | CRITICAL | Patched | 9.9 | 2026-07-23 | 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL… |
| CVE-2024-58354 | CRITICAL | 9.9 | 2026-07-23 | cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_req… | |
| CVE-2026-47724 | CRITICAL | 9.9 | 2026-07-23 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trusts the bearer token alon… |