Search
34,854 CVEs · Critical severity
CVEs (34,854, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 34,854 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-77535 | CRITICAL | 9.1 | 2026-08-26 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Co… | |
| CVE-2026-77534 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate… | |
| CVE-2026-59683 | CRITICAL | 9.8 | 2026-08-26 | The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of CVE-2026-59682). This allows either a full system co… | |
| CVE-2026-59682 | CRITICAL | 9.1 | 2026-08-26 | Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3. | |
| CVE-2026-80235 | CRITICAL | 9.8 | 2026-08-26 | EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, th… | |
| CVE-2026-77533 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Com… | |
| CVE-2026-18431 | CRITICAL | 9.8 | 2026-08-26 | The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in ver… | |
| CVE-2026-19632 | CRITICAL | 9.8 | 2026-08-26 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… | |
| CVE-2026-80138 | CRITICAL | 9.8 | 2026-08-25 | ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit… | |
| CVE-2026-79911 | CRITICAL | 10.0 | 2026-08-25 | A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi o… | |
| CVE-2026-16645 | CRITICAL | 9.1 | 2026-08-25 | Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive Ja… | |
| CVE-2026-16644 | CRITICAL | 9.1 | 2026-08-25 | Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0. | |
| CVE-2026-16641 | CRITICAL | 9.8 | 2026-08-25 | Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*. | |
| CVE-2026-16639 | CRITICAL | 9.8 | 2026-08-25 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Intern… | |
| CVE-2026-78655 | CRITICAL | Patched | 9.1 | 2026-08-25 | Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts… |
| CVE-2026-78619 | CRITICAL | Patched | 9.8 | 2026-08-25 | Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers nume… |
| CVE-2026-68525 | CRITICAL | Patched | 9.1 | 2026-08-25 | Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource… |
| CVE-2026-65905 | CRITICAL | Patched | 9.8 | 2026-08-25 | Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authe… |
| CVE-2026-65637 | CRITICAL | Patched | 9.8 | 2026-08-25 | Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 1… |
| CVE-2026-65182 | CRITICAL | Patched | 9.1 | 2026-08-25 | Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a … |
| CVE-2026-80104 | CRITICAL | 9.8 | 2026-08-25 | DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src… | |
| CVE-2026-79290 | CRITICAL | Patched | 9.6 | 2026-08-25 | Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium se… |
| CVE-2026-79282 | CRITICAL | Patched | 9.6 | 2026-08-25 | Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML pag… |
| CVE-2026-79275 | CRITICAL | Patched | 9.6 | 2026-08-25 | Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium s… |
| CVE-2026-79257 | CRITICAL | Patched | 9.6 | 2026-08-25 | Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium s… |