Search
32,629 CVEs · Critical severity
CVEs (32,629, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 32,629 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50148 | CRITICAL | Patched | 10.0 | 2026-07-15 | Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase… |
| CVE-2026-56699 | CRITICAL | Patched | 10.0 | 2026-07-15 | Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON o… |
| CVE-2026-15409 | CRITICAL | 10.0 | 2026-07-14 | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially ca… | |
| CVE-2026-62422 | CRITICAL | Patched | 10.0 | 2026-07-14 | In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leadin… |
| CVE-2026-56451 | CRITICAL | 10.0 | 2026-07-14 | A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT)… | |
| CVE-2026-57811 | CRITICAL | 10.0 | 2026-07-13 | Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusio… | |
| CVE-2026-57719 | CRITICAL | 10.0 | 2026-07-13 | Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/… | |
| CVE-2026-61447 | CRITICAL | Patched | 10.0 | 2026-07-11 | PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import… |
| CVE-2026-54769 | CRITICAL | 10.0 | 2026-07-10 | Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code … | |
| CVE-2026-59726 | CRITICAL | Patched | 10.0 | 2026-07-09 | Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group e… |
| CVE-2026-54782 | CRITICAL | Patched | 10.0 | 2026-07-08 | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does … |
| CVE-2026-57572 | CRITICAL | Patched | 10.0 | 2026-07-06 | Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed int… |
| CVE-2026-54763 | CRITICAL | Patched | 10.0 | 2026-07-06 | Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cas… |
| CVE-2026-48316 | CRITICAL | 10.0 | 2026-07-06 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of t… | |
| CVE-2026-13768 | CRITICAL | 10.0 | 2026-07-03 | Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection in… | |
| CVE-2026-56004 | CRITICAL | 10.0 | 2026-07-02 | A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute… | |
| CVE-2026-50746 | CRITICAL | Patched | 10.0 | 2026-07-02 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the… |
| CVE-2026-57624 | CRITICAL | 10.0 | 2026-07-02 | Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions. | |
| CVE-2026-50160 | CRITICAL | Patched | 10.0 | 2026-07-01 | Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated POST /v1/onboarding/conf… |
| CVE-2026-56413 | CRITICAL | 10.0 | 2026-06-30 | Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom netwo… | |
| CVE-2026-56415 | CRITICAL | 10.0 | 2026-06-30 | Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submi… | |
| CVE-2026-13782 | CRITICAL | Patched | 10.0 | 2026-06-30 | Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape… |
| CVE-2026-10134 | CRITICAL | Patched | 10.0 | 2026-06-30 | IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, file uplo… |
| CVE-2026-48276 | CRITICAL | 10.0 | 2026-06-30 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code executi… | |
| CVE-2026-48277 | CRITICAL | 10.0 | 2026-06-30 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of t… |