Search
34,865 CVEs · Critical severity
CVEs (34,865, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 34,865 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-78032 | CRITICAL | 9.8 | 2026-08-28 | SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege. | |
| CVE-2026-7803 | CRITICAL | Patched | 9.8 | 2026-06-30 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component type fields. |
| CVE-2026-78012 | CRITICAL | 9.8 | 2026-09-01 | An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generat… | |
| CVE-2026-78003 | CRITICAL | 9.8 | 2026-08-22 | The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to … | |
| CVE-2026-77946 | CRITICAL | 10.0 | 2026-08-22 | A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the comp… | |
| CVE-2026-77915 | CRITICAL | Patched | 9.8 | 2026-08-24 | rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator pri… |
| CVE-2026-7786 | CRITICAL | 9.8 | 2026-05-29 | Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credentials embedded in the firmwar… | |
| CVE-2026-77810 | CRITICAL | Patched | 9.9 | 2026-08-21 | In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector… |
| CVE-2026-77806 | CRITICAL | Patched | 9.8 | 2026-08-21 | SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Sp… |
| CVE-2026-77776 | CRITICAL | 9.1 | 2026-08-21 | Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py… | |
| CVE-2026-77683 | CRITICAL | 9.9 | 2026-08-21 | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezo… | |
| CVE-2026-77651 | CRITICAL | 9.8 | 2026-08-21 | The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers wi… | |
| CVE-2026-77650 | CRITICAL | 9.8 | 2026-08-21 | The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that regist… | |
| CVE-2026-77649 | CRITICAL | 9.8 | 2026-08-21 | The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers w… | |
| CVE-2026-77647 | CRITICAL | Patched | 9.8 | 2026-08-20 | SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification o… |
| CVE-2026-7763 | CRITICAL | 9.8 | 2026-06-05 | A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated… | |
| CVE-2026-7762 | CRITICAL | 9.8 | 2026-06-05 | A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticat… | |
| CVE-2026-77557 | CRITICAL | 9.8 | 2026-08-26 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on the device. | |
| CVE-2026-77554 | CRITICAL | 10.0 | 2026-08-26 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the … | |
| CVE-2026-77553 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privile… | |
| CVE-2026-77552 | CRITICAL | 9.8 | 2026-08-26 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Video Bridge to execute a Command Inje… | |
| CVE-2026-77551 | CRITICAL | 9.0 | 2026-08-26 | A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Connect Display Cast Pro to … | |
| CVE-2026-77550 | CRITICAL | 10.0 | 2026-08-26 | A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass au… | |
| CVE-2026-77549 | CRITICAL | 9.0 | 2026-08-26 | A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices … | |
| CVE-2026-77548 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Com… |