Search
7,875 CVEs · Critical severity
CVEs (7,875, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 7,875 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-18922 | CRITICAL | 9.8 | 2026-09-07 | A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can… | |
| CVE-2026-80238 | CRITICAL | 9.3 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerabili… | |
| CVE-2026-76578 | CRITICAL | 9.8 | 2026-09-07 | A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. A… | |
| CVE-2026-6223 | CRITICAL | 9.4 | 2026-09-07 | Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality BiHayat App allows Authentication Bypass. This issue affects BiHayat Ap… | |
| CVE-2026-61410 | CRITICAL | 9.4 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authorization vulnerability. An unauthenti… | |
| CVE-2026-86299 | CRITICAL | 9.9 | 2026-09-07 | A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Ha… | |
| CVE-2026-86296 | CRITICAL | 10.0 | 2026-09-07 | A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This ma… | |
| CVE-2026-79698 | CRITICAL | 9.9 | 2026-09-07 | A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-66… | |
| CVE-2026-79697 | CRITICAL | 9.9 | 2026-09-07 | A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-66… | |
| CVE-2026-86167 | CRITICAL | 9.9 | 2026-09-06 | A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation… | |
| CVE-2026-86165 | CRITICAL | 9.8 | 2026-09-06 | A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argu… | |
| CVE-2026-75816 | CRITICAL | 9.8 | 2026-09-06 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due … | |
| CVE-2026-16310 | CRITICAL | 9.8 | 2026-09-06 | The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing vali… | |
| CVE-2026-86153 | CRITICAL | 9.1 | 2026-09-06 | A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation lead… | |
| CVE-2026-86152 | CRITICAL | 10.0 | 2026-09-06 | A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. … | |
| CVE-2026-86151 | CRITICAL | 9.1 | 2026-09-06 | A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Mana… | |
| CVE-2026-86149 | CRITICAL | 9.1 | 2026-09-05 | A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument inte… | |
| CVE-2026-86148 | CRITICAL | 9.1 | 2026-09-05 | A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipu… | |
| CVE-2026-86190 | CRITICAL | 9.1 | 2026-09-05 | WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and li… | |
| CVE-2026-86189 | CRITICAL | 9.8 | 2026-09-05 | WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a cal… | |
| CVE-2026-86184 | CRITICAL | Patched | 9.8 | 2026-09-05 | Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user … |
| CVE-2026-10196 | CRITICAL | Patched | 9.8 | 2026-09-05 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc… |
| CVE-2026-86124 | CRITICAL | 9.8 | 2026-09-05 | AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. At… | |
| CVE-2026-86121 | CRITICAL | Patched | 9.8 | 2026-09-05 | Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthe… |
| CVE-2024-11080 | CRITICAL | 9.8 | 2026-09-05 | The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in t… |