Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

34,865 CVEs · Critical severity

CVEs (34,865, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 26–50 of 34,865 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-73053 CRITICAL 9.0 2026-08-15 SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft…
CVE-2026-73042 CRITICAL 9.0 2026-08-15 SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-e…
CVE-2026-73043 CRITICAL 9.0 2026-08-15 SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output…
CVE-2026-73044 CRITICAL 9.0 2026-08-15 SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inje…
CVE-2026-73050 CRITICAL 9.0 2026-08-15 SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped rend…
CVE-2026-73041 CRITICAL 9.0 2026-08-15 SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into ann…
CVE-2026-72279 CRITICAL 9.0 2026-08-15 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR KVM currently maps the L1 VNCR into the hos…
CVE-2026-73842 CRITICAL Patched 9.0 2026-08-13 OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api…
CVE-2026-71471 CRITICAL 9.0 2026-08-12 A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), c…
CVE-2026-48381 CRITICAL Patched 9.0 2026-08-11 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbit…
CVE-2026-71851 CRITICAL Patched 9.0 2026-08-07 crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation …
CVE-2025-14561 CRITICAL 9.0 2026-08-06 In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invok…
CVE-2026-70426 CRITICAL 9.0 2026-08-05 In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not …
CVE-2026-20267 CRITICAL 9.0 2026-08-05 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security …
CVE-2026-10090 CRITICAL 9.0 2026-08-05 A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with n…
CVE-2026-17351 CRITICAL Patched 9.0 2026-07-31 The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-…
CVE-2026-18245 CRITICAL Patched 9.0 2026-07-30 Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user brow…
CVE-2026-14602 CRITICAL 9.0 2026-07-30 The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary…
CVE-2026-14289 CRITICAL Patched 9.0 2026-07-27 The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a crypto…
CVE-2026-16723 CRITICAL 9.0 2026-07-23 A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no Au…
CVE-2026-61223 CRITICAL 9.0 2026-07-21 Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). Supported versions that are affected are 8.…
CVE-2026-61204 CRITICAL 9.0 2026-07-21 Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). The supported version that is affected …
CVE-2026-61201 CRITICAL 9.0 2026-07-21 Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.2.23. …
CVE-2026-61174 CRITICAL 9.0 2026-07-21 Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. …
CVE-2026-60424 CRITICAL 9.0 2026-07-21 Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.…