Search
34,854 CVEs · Critical severity
CVEs (34,854, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 34,854 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-75325 | CRITICAL | 9.8 | 2026-08-26 | DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters. | |
| CVE-2026-70419 | CRITICAL | Patched | 9.1 | 2026-08-26 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. … |
| CVE-2026-51106 | CRITICAL | 9.3 | 2026-08-26 | An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component | |
| CVE-2025-61165 | CRITICAL | 9.8 | 2026-08-26 | An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file. | |
| CVE-2025-61163 | CRITICAL | 9.8 | 2026-08-26 | Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origi… | |
| CVE-2023-42179 | CRITICAL | 9.8 | 2026-08-26 | Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process. | |
| CVE-2026-81032 | CRITICAL | 9.8 | 2026-08-26 | NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind … | |
| CVE-2026-80428 | CRITICAL | 9.8 | 2026-08-26 | ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code b… | |
| CVE-2026-54569 | CRITICAL | 9.8 | 2026-08-26 | SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote c… | |
| CVE-2026-80589 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: block: stop the timeout timer when releasing a never added disk disk_release() undoes blk_mq_init_allo… | |
| CVE-2026-80587 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboptions Some MPTCP suboptions are mutually exclusive according… | |
| CVE-2026-80586 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: mptcp: options: reset DSS fields in case of unexpected size A remote peer could send a malformed DSS w… | |
| CVE-2026-80585 | CRITICAL | 9.4 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with SYN data Passive TCP Fast Open accepts a valid-cookie S… | |
| CVE-2026-80561 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: libceph: fix multiple unsafe decodes in decode_locker() decode_locker() in cls_lock_client.c contains … | |
| CVE-2026-80558 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: libceph: Avoid using invalid osd indices from primary_temp A corrupted osdmap received from a Ceph mon… | |
| CVE-2026-80557 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: libceph: fix OOB read in decode_watchers() via missing bounds check ceph_start_decoding() validates th… | |
| CVE-2026-80554 | CRITICAL | 9.3 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Limit the number of channel program segments The processing of channel programs, and th… | |
| CVE-2026-80551 | CRITICAL | 9.3 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Ensure first IDAW remains constant The first IDAW in a list does not need to be on a 2K… | |
| CVE-2026-80528 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: ceph: avoid fs reclaim while using current->journal_info handle_reply() stores a `ceph_mds_request` po… | |
| CVE-2026-80519 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: ovpn: finish crypto callback cleanup before peer release Crypto completion callbacks hold both key-slo… | |
| CVE-2026-74752 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: sctp: validate cookie AUTH state before use When cookie authentication is disabled, COOKIE_ECHO restor… | |
| CVE-2026-74751 | CRITICAL | 9.4 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: riscv: lib: Fix ZBB strnlen reading past count boundary The ZBB-optimized strnlen loop loads one word … | |
| CVE-2026-74746 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: publish GC-visible tuple last nf_flow_table_iterate() only treats original-direc… | |
| CVE-2026-74744 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev ipvlan devices inherit hard_header_le… | |
| CVE-2026-74743 | CRITICAL | 9.8 | 2026-08-26 | In the Linux kernel, the following vulnerability has been resolved: macvlan: inherit needed_headroom and needed_tailroom from lowerdev macvlan devices inherit hard_header… |