Search
34,969 CVEs · Critical severity
CVEs (34,969, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 34,969 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77554 | CRITICAL | 10.0 | 2026-08-26 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the … | |
| CVE-2026-77550 | CRITICAL | 10.0 | 2026-08-26 | A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass au… | |
| CVE-2026-77537 | CRITICAL | 10.0 | 2026-08-26 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on t… | |
| CVE-2026-79911 | CRITICAL | 10.0 | 2026-08-25 | A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi o… | |
| CVE-2026-76197 | CRITICAL | Patched | 10.0 | 2026-08-25 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in… |
| CVE-2026-76193 | CRITICAL | Patched | 10.0 | 2026-08-25 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current u… |
| CVE-2026-76195 | CRITICAL | Patched | 10.0 | 2026-08-25 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in… |
| CVE-2026-78167 | CRITICAL | 10.0 | 2026-08-24 | A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. Th… | |
| CVE-2026-74705 | CRITICAL | 10.0 | 2026-08-22 | In the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel segmentation __skb_udp_tunnel_segment() gets the UDP heade… | |
| CVE-2026-74612 | CRITICAL | 10.0 | 2026-08-22 | In the Linux kernel, the following vulnerability has been resolved: veth: fix skb length accounting after XDP frag adjustment veth exposes non-linear skb fragments throug… | |
| CVE-2026-77946 | CRITICAL | 10.0 | 2026-08-22 | A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the comp… | |
| CVE-2026-61539 | CRITICAL | Patched | 10.0 | 2026-08-21 | Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output t… |
| CVE-2026-69502 | CRITICAL | 10.0 | 2026-08-21 | Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-69555 | CRITICAL | 10.0 | 2026-08-20 | Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-69836 | CRITICAL | 10.0 | 2026-08-20 | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. | |
| CVE-2026-65816 | CRITICAL | 10.0 | 2026-08-20 | Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-65801 | CRITICAL | 10.0 | 2026-08-20 | Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-65770 | CRITICAL | 10.0 | 2026-08-20 | Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute… | |
| CVE-2026-22306 | CRITICAL | Patched | 10.0 | 2026-08-19 | Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Oz… |
| CVE-2026-20357 | CRITICAL | 10.0 | 2026-08-19 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review… | |
| CVE-2026-20358 | CRITICAL | 10.0 | 2026-08-19 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review… | |
| CVE-2026-20315 | CRITICAL | 10.0 | 2026-08-19 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security … | |
| CVE-2026-20317 | CRITICAL | 10.0 | 2026-08-19 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security … | |
| CVE-2026-20030 | CRITICAL | 10.0 | 2026-08-19 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review… | |
| CVE-2026-18051 | CRITICAL | Patched | 10.0 | 2026-08-19 | The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write… |