Search
34,865 CVEs · Critical severity
CVEs (34,865, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 51–75 of 34,865 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-60249 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 an… | |
| CVE-2026-35198 | CRITICAL | 9.0 | 2026-07-20 | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team memb… | |
| CVE-2026-12701 | CRITICAL | 9.0 | 2026-07-20 | A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directo… | |
| CVE-2026-64106 | CRITICAL | Patched | 9.0 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits Userspace can restore an … |
| CVE-2026-11386 | CRITICAL | 9.0 | 2026-07-16 | An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /et… | |
| CVE-2026-62378 | CRITICAL | Patched | 9.0 | 2026-07-15 | RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/preview-modal.tsx and compo… |
| CVE-2026-48327 | CRITICAL | 9.0 | 2026-07-14 | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this is… | |
| CVE-2026-57898 | CRITICAL | Patched | 9.0 | 2026-07-14 | In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary fil… |
| CVE-2026-54527 | CRITICAL | Patched | 9.0 | 2026-07-08 | JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when re… |
| CVE-2026-4375 | CRITICAL | 9.0 | 2026-07-07 | The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, … | |
| CVE-2026-58289 | CRITICAL | Patched | 9.0 | 2026-07-03 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-55116 | CRITICAL | Patched | 9.0 | 2026-07-02 | A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices runnin… |
| CVE-2026-57623 | CRITICAL | 9.0 | 2026-07-02 | Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions. | |
| CVE-2025-23350 | CRITICAL | 9.0 | 2026-07-01 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by craft… | |
| CVE-2025-23351 | CRITICAL | 9.0 | 2026-07-01 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by craft… | |
| CVE-2026-10539 | CRITICAL | 9.0 | 2026-07-01 | A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated att… | |
| CVE-2026-54636 | CRITICAL | Patched | 9.0 | 2026-06-26 | Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron co… |
| CVE-2026-45405 | CRITICAL | Patched | 9.0 | 2026-06-26 | Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/zip archives into temporary directories without sanit… |
| CVE-2026-45406 | CRITICAL | Patched | 9.0 | 2026-06-26 | Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-includes/ git repository directory to the host and th… |
| CVE-2026-45408 | CRITICAL | Patched | 9.0 | 2026-06-26 | Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authenticated user pushes to a g… |
| CVE-2026-55570 | CRITICAL | Patched | 9.0 | 2026-06-24 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, description) when they are se… |
| CVE-2026-54157 | CRITICAL | Patched | 9.0 | 2026-06-23 | LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.57, the /webapi/proxy endpoint on app.lobehub.co… |
| CVE-2026-44792 | CRITICAL | Patched | 9.0 | 2026-06-23 | n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository connected to an n8n Source Co… |
| CVE-2026-11374 | CRITICAL | 9.0 | 2026-06-23 | In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by… | |
| CVE-2026-12249 | CRITICAL | Patched | 9.0 | 2026-06-22 | An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendo… |