Search
34,865 CVEs · Critical severity
CVEs (34,865, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 34,865 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77547 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Comm… | |
| CVE-2026-77546 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Comm… | |
| CVE-2026-77545 | CRITICAL | 9.0 | 2026-08-26 | A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running … | |
| CVE-2026-77543 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Comm… | |
| CVE-2026-77542 | CRITICAL | 9.1 | 2026-08-26 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command… | |
| CVE-2026-77541 | CRITICAL | 9.1 | 2026-08-26 | A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privi… | |
| CVE-2026-77540 | CRITICAL | 9.1 | 2026-08-26 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Inje… | |
| CVE-2026-77539 | CRITICAL | 9.1 | 2026-08-26 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Inje… | |
| CVE-2026-77537 | CRITICAL | 10.0 | 2026-08-26 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on t… | |
| CVE-2026-77536 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate… | |
| CVE-2026-77535 | CRITICAL | 9.1 | 2026-08-26 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Co… | |
| CVE-2026-77534 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate… | |
| CVE-2026-77533 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Com… | |
| CVE-2026-77532 | CRITICAL | 9.6 | 2026-08-26 | A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwitch to initiate a Remote Code Ex… | |
| CVE-2026-7747 | CRITICAL | 9.8 | 2026-05-04 | A security flaw has been discovered in Totolink N300RH 3.2.4-B20220812. Affected by this vulnerability is the function loginauth of the file /cgi-bin/cstecgi.cgi of the com… | |
| CVE-2026-77264 | CRITICAL | 9.8 | 2026-08-21 | The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, an… | |
| CVE-2026-7719 | CRITICAL | 9.8 | 2026-05-04 | A security flaw has been discovered in Totolink WA300 5.2cu.7112_B20190227. The affected element is the function loginauth of the file /cgi-bin/cstecgi.cgi of the component… | |
| CVE-2026-77148 | CRITICAL | 9.9 | 2026-08-20 | A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET§ion=ptest_channel of the componen… | |
| CVE-2026-77087 | CRITICAL | Patched | 9.6 | 2026-08-21 | Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can cra… |
| CVE-2026-77086 | CRITICAL | 9.1 | 2026-08-21 | SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal … | |
| CVE-2026-77071 | CRITICAL | Patched | 9.8 | 2026-08-20 | n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row Get Many, Delete, and Update operations, which built … |
| CVE-2026-77070 | CRITICAL | Patched | 9.8 | 2026-08-20 | n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggregate operations, which parse the Query paramet… |
| CVE-2026-77022 | CRITICAL | 9.9 | 2026-08-20 | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_… | |
| CVE-2026-77016 | CRITICAL | Patched | 9.6 | 2026-08-27 | The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored fil… |
| CVE-2026-77012 | CRITICAL | 9.3 | 2026-08-29 | The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, … |