Search
32,629 CVEs · Critical severity
CVEs (32,629, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 32,629 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15982 | CRITICAL | 9.8 | 2026-07-17 | The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i… | |
| CVE-2026-62241 | CRITICAL | Patched | 9.1 | 2026-07-17 | clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.exam… |
| CVE-2026-14956 | CRITICAL | 9.8 | 2026-07-17 | The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds… | |
| CVE-2026-57075 | CRITICAL | Patched | 9.1 | 2026-07-16 | YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec. The base64 decoder in the bundled libsyck inde… |
| CVE-2026-53412 | CRITICAL | 9.8 | 2026-07-16 | Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an … | |
| CVE-2026-44180 | CRITICAL | Patched | 9.8 | 2026-07-16 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Versions 2.0.0rc1 and above… |
| CVE-2026-38158 | CRITICAL | 9.8 | 2026-07-16 | A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL s… | |
| CVE-2026-63089 | CRITICAL | Patched | 9.3 | 2026-07-16 | WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network a… |
| CVE-2026-46512 | CRITICAL | Patched | 9.9 | 2026-07-16 | Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, dest, url, extension, cod… |
| CVE-2026-45336 | CRITICAL | 10.0 | 2026-07-16 | HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-… | |
| CVE-2026-57073 | CRITICAL | 9.1 | 2026-07-16 | HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA"… | |
| CVE-2026-57074 | CRITICAL | 9.1 | 2026-07-16 | XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" … | |
| CVE-2026-63087 | CRITICAL | 9.8 | 2026-07-16 | Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to … | |
| CVE-2026-46621 | CRITICAL | Patched | 9.1 | 2026-07-16 | Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm… |
| CVE-2026-44632 | CRITICAL | Patched | 9.1 | 2026-07-16 | Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.Java… |
| CVE-2026-45568 | CRITICAL | Patched | 9.1 | 2026-07-16 | zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the reque… |
| CVE-2026-46562 | CRITICAL | Patched | 9.8 | 2026-07-16 | Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yam… |
| CVE-2026-3031 | CRITICAL | 9.8 | 2026-07-16 | Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg 0.9.0 that was last updated in 2004. Epeg is a fas… | |
| CVE-2026-45695 | CRITICAL | Patched | 9.8 | 2026-07-16 | Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. P… |
| CVE-2026-14890 | CRITICAL | 9.1 | 2026-07-16 | SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization sa… | |
| CVE-2026-11386 | CRITICAL | 9.0 | 2026-07-16 | An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /et… | |
| CVE-2023-49900 | CRITICAL | 9.8 | 2026-07-16 | An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command. | |
| CVE-2023-49899 | CRITICAL | 9.8 | 2026-07-16 | An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel. | |
| CVE-2026-22752 | CRITICAL | 9.6 | 2026-07-16 | Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through … | |
| CVE-2026-12492 | CRITICAL | Patched | 9.8 | 2026-07-16 | The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on… |