Search
32,629 CVEs · Critical severity
CVEs (32,629, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 51–75 of 32,629 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48150 | CRITICAL | Patched | 9.0 | 2026-05-27 | Budibase is an open-source low-code platform. Prior to 3.39.0, /api/public/v1/roles/assign is guarded by the builderOrAdmin middleware, which passes any user who is a build… |
| CVE-2026-45721 | CRITICAL | Patched | 9.0 | 2026-05-26 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that resolves to a directory without an index file, DirPage … |
| CVE-2026-4480 | CRITICAL | Patched | 9.0 | 2026-05-26 | A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via t… |
| CVE-2026-2651 | CRITICAL | Patched | 9.0 | 2026-05-25 | A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorizat… |
| CVE-2026-22314 | CRITICAL | 9.0 | 2026-05-20 | Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on… | |
| CVE-2026-45375 | CRITICAL | Patched | 9.0 | 2026-05-14 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan's Bazaar (community marketplace) renders the name and version fields of a package's pl… |
| CVE-2026-42457 | CRITICAL | Patched | 9.0 | 2026-05-14 | vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0, there is… |
| CVE-2026-41901 | CRITICAL | Patched | 9.0 | 2026-05-12 | Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypass vulnerability exists in the expression execut… |
| CVE-2026-44221 | CRITICAL | Patched | 9.0 | 2026-05-12 | ArcadeDB is a Multi-Model DBMS. Prior to 2.6.4, authenticated users and API tokens scoped to a specific database could read, write, and mutate schema on any other database … |
| CVE-2026-41588 | CRITICAL | Patched | 9.0 | 2026-05-08 | RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been patch… |
| CVE-2026-33844 | CRITICAL | 9.0 | 2026-05-07 | Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. | |
| CVE-2026-42370 | CRITICAL | Patched | 9.0 | 2026-05-04 | A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary cod… |
| CVE-2026-7372 | CRITICAL | Patched | 9.0 | 2026-05-04 | A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary cod… |
| CVE-2026-30893 | CRITICAL | Patched | 9.0 | 2026-04-29 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in… |
| CVE-2026-42523 | CRITICAL | Patched | 9.0 | 2026-04-29 | Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITS… |
| CVE-2026-5652 | CRITICAL | Patched | 9.0 | 2026-04-21 | An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actio… |
| CVE-2026-40569 | CRITICAL | 9.0 | 2026-04-21 | FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerability in the mailbox connection settings endpoints of… | |
| CVE-2026-24467 | CRITICAL | Patched | 9.0 | 2026-04-20 | OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests. Starting in version 1.0.0 and prior t… |
| CVE-2026-40572 | CRITICAL | Patched | 9.0 | 2026-04-18 | NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user-mode processes to map… |
| CVE-2026-40477 | CRITICAL | Patched | 9.0 | 2026-04-17 | Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the express… |
| CVE-2026-40478 | CRITICAL | Patched | 9.0 | 2026-04-17 | Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the exp… |
| CVE-2026-40322 | CRITICAL | Patched | 9.0 | 2026-04-16 | SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "loose", and the resulti… |
| CVE-2026-26149 | CRITICAL | Patched | 9.0 | 2026-04-14 | Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-39860 | CRITICAL | Patched | 9.0 | 2026-04-08 | Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchest… |
| CVE-2026-39846 | CRITICAL | Patched | 9.0 | 2026-04-07 | SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop c… |