Search
9,831 CVEs
CVEs (9,831, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 9,831 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55944 | CRITICAL | 9.8 | 2026-07-14 | Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network. | |
| CVE-2026-55010 | CRITICAL | 9.8 | 2026-07-14 | Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network. | |
| CVE-2026-50518 | CRITICAL | Patched | 9.8 | 2026-07-14 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-50447 | CRITICAL | Patched | 9.8 | 2026-07-14 | Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network. |
| CVE-2026-58644 | CRITICAL | Patched | 9.8 | 2026-07-14 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
| CVE-2026-54990 | CRITICAL | Patched | 9.8 | 2026-07-14 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2026-50522 | CRITICAL | Patched | 9.8 | 2026-07-14 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
| CVE-2026-49172 | CRITICAL | Patched | 9.8 | 2026-07-14 | Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. |
| CVE-2026-42990 | CRITICAL | Patched | 9.8 | 2026-07-14 | Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. |
| CVE-2026-15701 | CRITICAL | 9.8 | 2026-07-14 | A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component li… | |
| CVE-2026-58479 | CRITICAL | Patched | 9.8 | 2026-07-14 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cr… |
| CVE-2026-62390 | CRITICAL | Patched | 9.8 | 2026-07-14 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the inj… |
| CVE-2026-62392 | CRITICAL | Patched | 9.8 | 2026-07-14 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to O… |
| CVE-2026-15043 | CRITICAL | Patched | 9.8 | 2026-07-14 | DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE pred… |
| CVE-2026-52533 | CRITICAL | 9.8 | 2026-07-13 | An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component file | |
| CVE-2026-59801 | CRITICAL | 9.8 | 2026-07-13 | 9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending r… | |
| CVE-2026-51540 | CRITICAL | 9.8 | 2026-07-13 | OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing of connected explicit m… | |
| CVE-2026-51821 | CRITICAL | 9.8 | 2026-07-13 | SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitrary code via the /user/getUserLogin endpoint | |
| CVE-2026-61500 | CRITICAL | 9.8 | 2026-07-13 | Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to una… | |
| CVE-2026-57433 | CRITICAL | Patched | 9.8 | 2026-07-13 | Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count fr… |
| CVE-2026-60121 | CRITICAL | 9.8 | 2026-07-13 | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary c… | |
| CVE-2026-61498 | CRITICAL | 9.8 | 2026-07-13 | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers … | |
| CVE-2026-57813 | CRITICAL | 9.8 | 2026-07-13 | Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3. | |
| CVE-2026-59518 | CRITICAL | 9.8 | 2026-07-13 | Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2. | |
| CVE-2026-57770 | CRITICAL | 9.8 | 2026-07-13 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a thro… |