Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

9,831 CVEs

CVEs (9,831, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 476–500 of 9,831 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-55944 CRITICAL 9.8 2026-07-14 Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
CVE-2026-55010 CRITICAL 9.8 2026-07-14 Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
CVE-2026-50518 CRITICAL Patched 9.8 2026-07-14 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-50447 CRITICAL Patched 9.8 2026-07-14 Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
CVE-2026-58644 CRITICAL Patched 9.8 2026-07-14 Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-54990 CRITICAL Patched 9.8 2026-07-14 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-50522 CRITICAL Patched 9.8 2026-07-14 Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-49172 CRITICAL Patched 9.8 2026-07-14 Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
CVE-2026-42990 CRITICAL Patched 9.8 2026-07-14 Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
CVE-2026-15701 CRITICAL 9.8 2026-07-14 A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component li…
CVE-2026-58479 CRITICAL Patched 9.8 2026-07-14 Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cr…
CVE-2026-62390 CRITICAL Patched 9.8 2026-07-14 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the inj…
CVE-2026-62392 CRITICAL Patched 9.8 2026-07-14 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to O…
CVE-2026-15043 CRITICAL Patched 9.8 2026-07-14 DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE pred&hellip;
CVE-2026-52533 CRITICAL 9.8 2026-07-13 An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component file
CVE-2026-59801 CRITICAL 9.8 2026-07-13 9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending r&hellip;
CVE-2026-51540 CRITICAL 9.8 2026-07-13 OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing of connected explicit m&hellip;
CVE-2026-51821 CRITICAL 9.8 2026-07-13 SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitrary code via the /user/getUserLogin endpoint
CVE-2026-61500 CRITICAL 9.8 2026-07-13 Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to una&hellip;
CVE-2026-57433 CRITICAL Patched 9.8 2026-07-13 Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count fr&hellip;
CVE-2026-60121 CRITICAL 9.8 2026-07-13 Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary c&hellip;
CVE-2026-61498 CRITICAL 9.8 2026-07-13 Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers &hellip;
CVE-2026-57813 CRITICAL 9.8 2026-07-13 Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3.
CVE-2026-59518 CRITICAL 9.8 2026-07-13 Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.
CVE-2026-57770 CRITICAL 9.8 2026-07-13 Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a thro&hellip;