Search
34,865 CVEs · Critical severity
CVEs (34,865, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 34,865 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-73053 | CRITICAL | 9.0 | 2026-08-15 | SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft… | |
| CVE-2026-73042 | CRITICAL | 9.0 | 2026-08-15 | SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-e… | |
| CVE-2026-73043 | CRITICAL | 9.0 | 2026-08-15 | SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output… | |
| CVE-2026-73044 | CRITICAL | 9.0 | 2026-08-15 | SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inje… | |
| CVE-2026-73050 | CRITICAL | 9.0 | 2026-08-15 | SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped rend… | |
| CVE-2026-73041 | CRITICAL | 9.0 | 2026-08-15 | SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into ann… | |
| CVE-2026-72279 | CRITICAL | 9.0 | 2026-08-15 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR KVM currently maps the L1 VNCR into the hos… | |
| CVE-2026-73842 | CRITICAL | Patched | 9.0 | 2026-08-13 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api… |
| CVE-2026-71471 | CRITICAL | 9.0 | 2026-08-12 | A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), c… | |
| CVE-2026-48381 | CRITICAL | Patched | 9.0 | 2026-08-11 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbit… |
| CVE-2026-71851 | CRITICAL | Patched | 9.0 | 2026-08-07 | crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation … |
| CVE-2025-14561 | CRITICAL | 9.0 | 2026-08-06 | In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invok… | |
| CVE-2026-70426 | CRITICAL | 9.0 | 2026-08-05 | In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not … | |
| CVE-2026-20267 | CRITICAL | 9.0 | 2026-08-05 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security … | |
| CVE-2026-10090 | CRITICAL | 9.0 | 2026-08-05 | A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with n… | |
| CVE-2026-17351 | CRITICAL | Patched | 9.0 | 2026-07-31 | The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-… |
| CVE-2026-18245 | CRITICAL | Patched | 9.0 | 2026-07-30 | Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user brow… |
| CVE-2026-14602 | CRITICAL | 9.0 | 2026-07-30 | The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary… | |
| CVE-2026-14289 | CRITICAL | Patched | 9.0 | 2026-07-27 | The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a crypto… |
| CVE-2026-16723 | CRITICAL | 9.0 | 2026-07-23 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no Au… | |
| CVE-2026-61223 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). Supported versions that are affected are 8.… | |
| CVE-2026-61204 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). The supported version that is affected … | |
| CVE-2026-61201 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.2.23. … | |
| CVE-2026-61174 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. … | |
| CVE-2026-60424 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.… |