Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

34,854 CVEs · Critical severity

CVEs (34,854, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 476–500 of 34,854 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-77535 CRITICAL 9.1 2026-08-26 A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Co…
CVE-2026-77534 CRITICAL 9.9 2026-08-26 A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate…
CVE-2026-59683 CRITICAL 9.8 2026-08-26 The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of CVE-2026-59682). This allows either a full system co…
CVE-2026-59682 CRITICAL 9.1 2026-08-26 Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3.
CVE-2026-80235 CRITICAL 9.8 2026-08-26 EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, th…
CVE-2026-77533 CRITICAL 9.9 2026-08-26 A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Com…
CVE-2026-18431 CRITICAL 9.8 2026-08-26 The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in ver…
CVE-2026-19632 CRITICAL 9.8 2026-08-26 The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ…
CVE-2026-80138 CRITICAL 9.8 2026-08-25 ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit…
CVE-2026-79911 CRITICAL 10.0 2026-08-25 A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi o…
CVE-2026-16645 CRITICAL 9.1 2026-08-25 Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive Ja…
CVE-2026-16644 CRITICAL 9.1 2026-08-25 Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.
CVE-2026-16641 CRITICAL 9.8 2026-08-25 Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.
CVE-2026-16639 CRITICAL 9.8 2026-08-25 Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Intern…
CVE-2026-78655 CRITICAL Patched 9.1 2026-08-25 Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts…
CVE-2026-78619 CRITICAL Patched 9.8 2026-08-25 Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers nume…
CVE-2026-68525 CRITICAL Patched 9.1 2026-08-25 Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource…
CVE-2026-65905 CRITICAL Patched 9.8 2026-08-25 Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authe…
CVE-2026-65637 CRITICAL Patched 9.8 2026-08-25 Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 1…
CVE-2026-65182 CRITICAL Patched 9.1 2026-08-25 Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a …
CVE-2026-80104 CRITICAL 9.8 2026-08-25 DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src…
CVE-2026-79290 CRITICAL Patched 9.6 2026-08-25 Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium se…
CVE-2026-79282 CRITICAL Patched 9.6 2026-08-25 Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML pag…
CVE-2026-79275 CRITICAL Patched 9.6 2026-08-25 Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium s…
CVE-2026-79257 CRITICAL Patched 9.6 2026-08-25 Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium s…