Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

9,841 CVEs

CVEs (9,841, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 451–475 of 9,841 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-44180 CRITICAL Patched 9.8 2026-07-16 Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Versions 2.0.0rc1 and above…
CVE-2026-38158 CRITICAL 9.8 2026-07-16 A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL s…
CVE-2026-63087 CRITICAL 9.8 2026-07-16 Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to …
CVE-2026-46562 CRITICAL Patched 9.8 2026-07-16 Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yam…
CVE-2026-3031 CRITICAL 9.8 2026-07-16 Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg 0.9.0 that was last updated in 2004. Epeg is a fas…
CVE-2026-45695 CRITICAL Patched 9.8 2026-07-16 Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. P…
CVE-2023-49900 CRITICAL 9.8 2026-07-16 An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.
CVE-2023-49899 CRITICAL 9.8 2026-07-16 An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.
CVE-2026-12492 CRITICAL Patched 9.8 2026-07-16 The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on…
CVE-2026-15013 CRITICAL 9.8 2026-07-16 The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including,…
CVE-2026-55652 CRITICAL Patched 9.8 2026-07-15 Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the c…
CVE-2026-30618 CRITICAL 9.8 2026-07-15 xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker can access the publicly…
CVE-2026-30623 CRITICAL 9.8 2026-07-15 LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configur…
CVE-2025-65720 CRITICAL 9.8 2026-07-15 An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page.
CVE-2026-51380 CRITICAL 9.8 2026-07-15 Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or potentially execute remote code via …
CVE-2026-49352 CRITICAL Patched 9.8 2026-07-15 9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in src/app/api/auth/login/r…
CVE-2026-14960 CRITICAL 9.8 2026-07-15 Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_REA…
CVE-2026-5269 CRITICAL 9.8 2026-07-14 In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accoun…
CVE-2026-5270 CRITICAL 9.8 2026-07-14 An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The i…
CVE-2026-51807 CRITICAL Patched 9.8 2026-07-14 Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (fixed in v0.18.4) caused by missing bounds validatio…
CVE-2026-51808 CRITICAL 9.8 2026-07-14 Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the openhtj2k_decoder_impl::invoke, invoke_line_based, invok…
CVE-2026-46634 CRITICAL Patched 9.8 2026-07-14 Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can &hellip;
CVE-2026-46633 CRITICAL Patched 9.8 2026-07-14 Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP sing&hellip;
CVE-2026-38450 CRITICAL 9.8 2026-07-14 An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of the Add/Update Project&hellip;
CVE-2026-53633 CRITICAL Patched 9.8 2026-07-14 Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools P&hellip;