Search
1,115 CVEs · Critical severity
CVEs (1,115, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 1,115 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-61949 | CRITICAL | 9.3 | 2026-07-23 | Unauthenticated SQL Injection in Bookly <= 27.7 versions. | |
| CVE-2026-61948 | CRITICAL | 9.3 | 2026-07-23 | Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions. | |
| CVE-2026-59555 | CRITICAL | 10.0 | 2026-07-23 | Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. | |
| CVE-2026-59544 | CRITICAL | 9.8 | 2026-07-23 | Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions. | |
| CVE-2026-59543 | CRITICAL | 9.9 | 2026-07-23 | Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions. | |
| CVE-2026-59540 | CRITICAL | 9.8 | 2026-07-23 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. | |
| CVE-2026-59526 | CRITICAL | 9.3 | 2026-07-23 | Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | |
| CVE-2026-59525 | CRITICAL | 9.3 | 2026-07-23 | Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. | |
| CVE-2026-59514 | CRITICAL | 9.3 | 2026-07-23 | Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions. | |
| CVE-2026-57784 | CRITICAL | 9.6 | 2026-07-23 | Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | |
| CVE-2026-27064 | CRITICAL | 9.1 | 2026-07-23 | Editor Arbitrary File Upload in Mailster <= 4.1.17 versions. | |
| CVE-2026-15015 | CRITICAL | 9.8 | 2026-07-23 | The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugi… | |
| CVE-2026-15011 | CRITICAL | 9.8 | 2026-07-23 | The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due … | |
| CVE-2026-14282 | CRITICAL | 9.8 | 2026-07-23 | The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in… | |
| CVE-2026-16723 | CRITICAL | 9.0 | 2026-07-23 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no Au… | |
| CVE-2026-60372 | CRITICAL | 9.8 | 2026-07-22 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a… | |
| CVE-2026-60369 | CRITICAL | 9.9 | 2026-07-22 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a… | |
| CVE-2026-60367 | CRITICAL | 9.8 | 2026-07-22 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a… | |
| CVE-2026-60366 | CRITICAL | 10.0 | 2026-07-22 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a… | |
| CVE-2026-46738 | CRITICAL | 9.1 | 2026-07-22 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote ac… | |
| CVE-2026-40712 | CRITICAL | 9.1 | 2026-07-22 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote ac… | |
| CVE-2026-16606 | CRITICAL | 9.8 | 2026-07-22 | A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-aut… | |
| CVE-2026-2395 | CRITICAL | 9.8 | 2026-07-22 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL … | |
| CVE-2026-62144 | CRITICAL | 9.1 | 2026-07-22 | An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administ… | |
| CVE-2026-16232 | CRITICAL | Patched | 9.1 | 2026-07-22 | An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use … |