Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

34,865 CVEs · Critical severity

CVEs (34,865, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 51–75 of 34,865 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-60249 CRITICAL 9.0 2026-07-21 Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 an…
CVE-2026-35198 CRITICAL 9.0 2026-07-20 HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team memb…
CVE-2026-12701 CRITICAL 9.0 2026-07-20 A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directo…
CVE-2026-64106 CRITICAL Patched 9.0 2026-07-19 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits Userspace can restore an …
CVE-2026-11386 CRITICAL 9.0 2026-07-16 An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /et…
CVE-2026-62378 CRITICAL Patched 9.0 2026-07-15 RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/preview-modal.tsx and compo…
CVE-2026-48327 CRITICAL 9.0 2026-07-14 ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this is…
CVE-2026-57898 CRITICAL Patched 9.0 2026-07-14 In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary fil…
CVE-2026-54527 CRITICAL Patched 9.0 2026-07-08 JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when re…
CVE-2026-4375 CRITICAL 9.0 2026-07-07 The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, …
CVE-2026-58289 CRITICAL Patched 9.0 2026-07-03 Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-55116 CRITICAL Patched 9.0 2026-07-02 A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices runnin…
CVE-2026-57623 CRITICAL 9.0 2026-07-02 Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.
CVE-2025-23350 CRITICAL 9.0 2026-07-01 NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by craft&hellip;
CVE-2025-23351 CRITICAL 9.0 2026-07-01 NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by craft&hellip;
CVE-2026-10539 CRITICAL 9.0 2026-07-01 A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated att&hellip;
CVE-2026-54636 CRITICAL Patched 9.0 2026-06-26 Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron co&hellip;
CVE-2026-45405 CRITICAL Patched 9.0 2026-06-26 Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/zip archives into temporary directories without sanit&hellip;
CVE-2026-45406 CRITICAL Patched 9.0 2026-06-26 Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-includes/ git repository directory to the host and th&hellip;
CVE-2026-45408 CRITICAL Patched 9.0 2026-06-26 Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authenticated user pushes to a g&hellip;
CVE-2026-55570 CRITICAL Patched 9.0 2026-06-24 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, description) when they are se&hellip;
CVE-2026-54157 CRITICAL Patched 9.0 2026-06-23 LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.57, the /webapi/proxy endpoint on app.lobehub.co&hellip;
CVE-2026-44792 CRITICAL Patched 9.0 2026-06-23 n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository connected to an n8n Source Co&hellip;
CVE-2026-11374 CRITICAL 9.0 2026-06-23 In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by&hellip;
CVE-2026-12249 CRITICAL Patched 9.0 2026-06-22 An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendo&hellip;