Search
9,841 CVEs
CVEs (9,841, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 9,841 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44180 | CRITICAL | Patched | 9.8 | 2026-07-16 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Versions 2.0.0rc1 and above… |
| CVE-2026-38158 | CRITICAL | 9.8 | 2026-07-16 | A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL s… | |
| CVE-2026-63087 | CRITICAL | 9.8 | 2026-07-16 | Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to … | |
| CVE-2026-46562 | CRITICAL | Patched | 9.8 | 2026-07-16 | Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yam… |
| CVE-2026-3031 | CRITICAL | 9.8 | 2026-07-16 | Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg 0.9.0 that was last updated in 2004. Epeg is a fas… | |
| CVE-2026-45695 | CRITICAL | Patched | 9.8 | 2026-07-16 | Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. P… |
| CVE-2023-49900 | CRITICAL | 9.8 | 2026-07-16 | An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command. | |
| CVE-2023-49899 | CRITICAL | 9.8 | 2026-07-16 | An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel. | |
| CVE-2026-12492 | CRITICAL | Patched | 9.8 | 2026-07-16 | The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on… |
| CVE-2026-15013 | CRITICAL | 9.8 | 2026-07-16 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including,… | |
| CVE-2026-55652 | CRITICAL | Patched | 9.8 | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the c… |
| CVE-2026-30618 | CRITICAL | 9.8 | 2026-07-15 | xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker can access the publicly… | |
| CVE-2026-30623 | CRITICAL | 9.8 | 2026-07-15 | LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configur… | |
| CVE-2025-65720 | CRITICAL | 9.8 | 2026-07-15 | An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page. | |
| CVE-2026-51380 | CRITICAL | 9.8 | 2026-07-15 | Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or potentially execute remote code via … | |
| CVE-2026-49352 | CRITICAL | Patched | 9.8 | 2026-07-15 | 9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in src/app/api/auth/login/r… |
| CVE-2026-14960 | CRITICAL | 9.8 | 2026-07-15 | Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_REA… | |
| CVE-2026-5269 | CRITICAL | 9.8 | 2026-07-14 | In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accoun… | |
| CVE-2026-5270 | CRITICAL | 9.8 | 2026-07-14 | An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The i… | |
| CVE-2026-51807 | CRITICAL | Patched | 9.8 | 2026-07-14 | Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (fixed in v0.18.4) caused by missing bounds validatio… |
| CVE-2026-51808 | CRITICAL | 9.8 | 2026-07-14 | Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the openhtj2k_decoder_impl::invoke, invoke_line_based, invok… | |
| CVE-2026-46634 | CRITICAL | Patched | 9.8 | 2026-07-14 | Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can … |
| CVE-2026-46633 | CRITICAL | Patched | 9.8 | 2026-07-14 | Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP sing… |
| CVE-2026-38450 | CRITICAL | 9.8 | 2026-07-14 | An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of the Add/Update Project… | |
| CVE-2026-53633 | CRITICAL | Patched | 9.8 | 2026-07-14 | Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools P… |