Search
3,684 CVEs · Critical severity
CVEs (3,684, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 51–75 of 3,684 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-78362 | CRITICAL | Patched | 9.8 | 2026-09-05 | The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be ser… |
| CVE-2026-83627 | CRITICAL | 9.8 | 2026-09-05 | The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21… | |
| CVE-2026-13447 | CRITICAL | 9.8 | 2026-09-05 | The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic sig… | |
| CVE-2026-52766 | CRITICAL | Patched | 9.1 | 2026-09-05 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array fro… |
| CVE-2026-75925 | CRITICAL | 9.6 | 2026-09-04 | Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by… | |
| CVE-2025-67066 | CRITICAL | 9.8 | 2026-09-04 | SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path | |
| CVE-2026-79391 | CRITICAL | 9.8 | 2026-09-04 | No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP port 1883 without requiring authentication, allowing a … | |
| CVE-2026-71624 | CRITICAL | 9.8 | 2026-09-04 | An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php,… | |
| CVE-2026-81939 | CRITICAL | 9.1 | 2026-09-04 | A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outsid… | |
| CVE-2026-78328 | CRITICAL | 9.1 | 2026-09-04 | A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileg… | |
| CVE-2026-78327 | CRITICAL | 9.1 | 2026-09-04 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Manageme… | |
| CVE-2026-78745 | CRITICAL | 9.8 | 2026-09-04 | An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via the Android Debug Bridge (ADB) daemon (adbd) | |
| CVE-2026-75430 | CRITICAL | 9.8 | 2026-09-04 | PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This all… | |
| CVE-2026-31020 | CRITICAL | 9.8 | 2026-09-04 | In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionalit… | |
| CVE-2026-75431 | CRITICAL | 9.1 | 2026-09-04 | PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code. | |
| CVE-2026-75160 | CRITICAL | 9.1 | 2026-09-04 | An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi. | |
| CVE-2026-44402 | CRITICAL | 9.8 | 2026-09-04 | Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to … | |
| CVE-2026-19274 | CRITICAL | 9.6 | 2026-09-04 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently dest… | |
| CVE-2026-18658 | CRITICAL | 9.8 | 2026-09-04 | IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execut… | |
| CVE-2026-85696 | CRITICAL | 9.8 | 2026-09-04 | SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper esc… | |
| CVE-2026-85695 | CRITICAL | 9.4 | 2026-09-04 | FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and p… | |
| CVE-2026-85688 | CRITICAL | 9.8 | 2026-09-04 | TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and … | |
| CVE-2026-85684 | CRITICAL | 9.1 | 2026-09-04 | marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attac… | |
| CVE-2026-85672 | CRITICAL | 9.8 | 2026-09-04 | zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated uns… | |
| CVE-2026-85667 | CRITICAL | 9.1 | 2026-09-04 | xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into t… |