Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

34,865 CVEs · Critical severity

CVEs (34,865, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 426–450 of 34,865 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-75329 CRITICAL 9.8 2026-08-26 The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configurat&hellip;
CVE-2026-75411 CRITICAL 9.8 2026-08-26 JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class e&hellip;
CVE-2026-75414 CRITICAL 9.8 2026-08-26 In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability.
CVE-2026-52103 CRITICAL 9.8 2026-08-26 A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands&hellip;
CVE-2025-51679 CRITICAL 9.1 2026-08-26 An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected behavior.
CVE-2026-75327 CRITICAL 9.8 2026-08-26 In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability:
CVE-2026-75334 CRITICAL 9.8 2026-08-26 The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql parameter is stored in the t_report_sql_resource table t&hellip;
CVE-2026-68000 CRITICAL 9.8 2026-08-26 The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directly concatenated into the LIMIT clause of SQL through &hellip;
CVE-2026-60004 CRITICAL Patched 9.8 2026-08-26 Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
CVE-2026-26448 CRITICAL 9.8 2026-08-26 Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection, and subsequently another client (or a later connect&hellip;
CVE-2025-70290 CRITICAL Patched 9.8 2026-08-26 An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The i&hellip;
CVE-2025-70293 CRITICAL Patched 9.8 2026-08-26 An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allo&hellip;
CVE-2026-75325 CRITICAL 9.8 2026-08-26 DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters.
CVE-2026-70419 CRITICAL Patched 9.1 2026-08-26 Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. &hellip;
CVE-2026-51106 CRITICAL 9.3 2026-08-26 An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component
CVE-2025-61163 CRITICAL 9.8 2026-08-26 Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origi&hellip;
CVE-2025-61165 CRITICAL 9.8 2026-08-26 An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file.
CVE-2023-42179 CRITICAL 9.8 2026-08-26 Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process.
CVE-2026-81032 CRITICAL 9.8 2026-08-26 NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind &hellip;
CVE-2026-80428 CRITICAL 9.8 2026-08-26 ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code b&hellip;
CVE-2026-54569 CRITICAL 9.8 2026-08-26 SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote c&hellip;
CVE-2026-80587 CRITICAL 9.8 2026-08-26 In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboptions Some MPTCP suboptions are mutually exclusive according&hellip;
CVE-2026-80589 CRITICAL 9.8 2026-08-26 In the Linux kernel, the following vulnerability has been resolved: block: stop the timeout timer when releasing a never added disk disk_release() undoes blk_mq_init_allo&hellip;
CVE-2026-80585 CRITICAL 9.4 2026-08-26 In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with SYN data Passive TCP Fast Open accepts a valid-cookie S&hellip;
CVE-2026-80586 CRITICAL 9.8 2026-08-26 In the Linux kernel, the following vulnerability has been resolved: mptcp: options: reset DSS fields in case of unexpected size A remote peer could send a malformed DSS w&hellip;