Search
34,865 CVEs · Critical severity
CVEs (34,865, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 34,865 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77549 | CRITICAL | 9.0 | 2026-08-26 | A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices … | |
| CVE-2026-77550 | CRITICAL | 10.0 | 2026-08-26 | A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass au… | |
| CVE-2026-18080 | CRITICAL | 9.8 | 2026-08-26 | The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including,… | |
| CVE-2026-80349 | CRITICAL | 9.8 | 2026-08-26 | TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header. app.js sets Koa's proxy option to true without naming which upstream p… | |
| CVE-2026-77541 | CRITICAL | 9.1 | 2026-08-26 | A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privi… | |
| CVE-2026-77542 | CRITICAL | 9.1 | 2026-08-26 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command… | |
| CVE-2026-77543 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Comm… | |
| CVE-2026-77545 | CRITICAL | 9.0 | 2026-08-26 | A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running … | |
| CVE-2026-59683 | CRITICAL | 9.8 | 2026-08-26 | The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of CVE-2026-59682). This allows either a full system co… | |
| CVE-2026-77534 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate… | |
| CVE-2026-77535 | CRITICAL | 9.1 | 2026-08-26 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Co… | |
| CVE-2026-77536 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate… | |
| CVE-2026-77537 | CRITICAL | 10.0 | 2026-08-26 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on t… | |
| CVE-2026-77539 | CRITICAL | 9.1 | 2026-08-26 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Inje… | |
| CVE-2026-77540 | CRITICAL | 9.1 | 2026-08-26 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Inje… | |
| CVE-2026-59682 | CRITICAL | 9.1 | 2026-08-26 | Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3. | |
| CVE-2026-80235 | CRITICAL | 9.8 | 2026-08-26 | EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, th… | |
| CVE-2026-77533 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Com… | |
| CVE-2026-18431 | CRITICAL | 9.8 | 2026-08-26 | The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in ver… | |
| CVE-2026-19632 | CRITICAL | 9.8 | 2026-08-26 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… | |
| CVE-2026-79911 | CRITICAL | 10.0 | 2026-08-25 | A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi o… | |
| CVE-2026-80138 | CRITICAL | 9.8 | 2026-08-25 | ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit… | |
| CVE-2026-16644 | CRITICAL | 9.1 | 2026-08-25 | Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0. | |
| CVE-2026-16645 | CRITICAL | 9.1 | 2026-08-25 | Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive Ja… | |
| CVE-2026-16639 | CRITICAL | 9.8 | 2026-08-25 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Intern… |