Search
34,702 CVEs · Critical severity
EOL hidden · Show all products
CVEs (34,702, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 34,702 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-75329 | CRITICAL | 9.8 | 2026-08-26 | The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configurat… | |
| CVE-2026-75414 | CRITICAL | 9.8 | 2026-08-26 | In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability. | |
| CVE-2026-75411 | CRITICAL | 9.8 | 2026-08-26 | JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class e… | |
| CVE-2026-52103 | CRITICAL | 9.8 | 2026-08-26 | A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands… | |
| CVE-2025-51679 | CRITICAL | 9.1 | 2026-08-26 | An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected behavior. | |
| CVE-2026-75334 | CRITICAL | 9.8 | 2026-08-26 | The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql parameter is stored in the t_report_sql_resource table t… | |
| CVE-2026-75327 | CRITICAL | 9.8 | 2026-08-26 | In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability: | |
| CVE-2026-68000 | CRITICAL | 9.8 | 2026-08-26 | The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directly concatenated into the LIMIT clause of SQL through … | |
| CVE-2026-60004 | CRITICAL | Patched | 9.8 | 2026-08-26 | Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. |
| CVE-2026-26448 | CRITICAL | 9.8 | 2026-08-26 | Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection, and subsequently another client (or a later connect… | |
| CVE-2025-70293 | CRITICAL | Patched | 9.8 | 2026-08-26 | An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allo… |
| CVE-2025-70290 | CRITICAL | Patched | 9.8 | 2026-08-26 | An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The i… |
| CVE-2026-75325 | CRITICAL | 9.8 | 2026-08-26 | DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters. | |
| CVE-2026-70419 | CRITICAL | Patched | 9.1 | 2026-08-26 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. … |
| CVE-2026-51106 | CRITICAL | 9.3 | 2026-08-26 | An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component | |
| CVE-2025-61165 | CRITICAL | 9.8 | 2026-08-26 | An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file. | |
| CVE-2025-61163 | CRITICAL | 9.8 | 2026-08-26 | Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origi… | |
| CVE-2023-42179 | CRITICAL | 9.8 | 2026-08-26 | Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process. | |
| CVE-2026-81032 | CRITICAL | 9.8 | 2026-08-26 | NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind … | |
| CVE-2026-80428 | CRITICAL | 9.8 | 2026-08-26 | ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code b… | |
| CVE-2026-54569 | CRITICAL | 9.8 | 2026-08-26 | SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote c… | |
| CVE-2026-80589 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: block: stop the timeout timer when releasing a never added disk disk_release() undoes blk_mq_init_allo… | |
| CVE-2026-80587 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboptions Some MPTCP suboptions are mutually exclusive according… | |
| CVE-2026-80586 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: mptcp: options: reset DSS fields in case of unexpected size A remote peer could send a malformed DSS w… | |
| CVE-2026-80585 | CRITICAL | 9.4 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with SYN data Passive TCP Fast Open accepts a valid-cookie S… |