Search
32,636 CVEs · Critical severity
CVEs (32,636, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 32,636 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53384 | CRITICAL | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails dw8250_probe() registers the 82… | |
| CVE-2026-16117 | CRITICAL | Patched | 10.0 | 2026-07-18 | Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes path… |
| CVE-2026-47865 | CRITICAL | Patched | 9.8 | 2026-07-18 | VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the … |
| CVE-2026-55518 | CRITICAL | Patched | 9.6 | 2026-07-17 | Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in the U… |
| CVE-2026-52348 | CRITICAL | 9.8 | 2026-07-17 | cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java. | |
| CVE-2026-54159 | CRITICAL | Patched | 10.0 | 2026-07-17 | PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected search filters from the … |
| CVE-2026-48062 | CRITICAL | Patched | 9.8 | 2026-07-17 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived gue… |
| CVE-2026-13446 | CRITICAL | Patched | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound c… |
| CVE-2026-8505 | CRITICAL | Patched | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The … |
| CVE-2026-8635 | CRITICAL | Patched | 9.9 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system command… |
| CVE-2026-8859 | CRITICAL | Patched | 9.9 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest c… |
| CVE-2026-8476 | CRITICAL | Patched | 9.9 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's uns… |
| CVE-2026-8481 | CRITICAL | Patched | 9.9 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint ac… |
| CVE-2026-63030 | CRITICAL | Patched | 9.8 | 2026-07-17 | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Inje… |
| CVE-2026-52199 | CRITICAL | 9.1 | 2026-07-17 | An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component | |
| CVE-2026-36669 | CRITICAL | 9.8 | 2026-07-17 | An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) … | |
| CVE-2026-42168 | CRITICAL | 9.1 | 2026-07-17 | django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. These fields are passed directly to os.system… | |
| CVE-2026-15091 | CRITICAL | 9.3 | 2026-07-17 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation. | |
| CVE-2025-51677 | CRITICAL | 9.1 | 2026-07-17 | An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can lead to unexpected behavior. | |
| CVE-2026-9103 | CRITICAL | Patched | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The… |
| CVE-2026-9135 | CRITICAL | Patched | 9.9 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies… |
| CVE-2026-9198 | CRITICAL | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code… | |
| CVE-2026-9202 | CRITICAL | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented … | |
| CVE-2026-8297 | CRITICAL | 9.8 | 2026-07-17 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Ser… | |
| CVE-2026-54496 | CRITICAL | Patched | 9.3 | 2026-07-17 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base sc… |