Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

32,629 CVEs · Critical severity

CVEs (32,629, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 76–100 of 32,629 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9051 CRITICAL 9.1 2026-05-29 There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentica…
CVE-2026-8959 CRITICAL Patched 9.6 2026-05-19 Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Th…
CVE-2026-8956 CRITICAL Patched 9.8 2026-05-19 Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
CVE-2026-8953 CRITICAL Patched 9.6 2026-05-19 Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbi…
CVE-2026-8950 CRITICAL Patched 9.3 2026-05-19 Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
CVE-2026-8948 CRITICAL Patched 9.1 2026-05-19 Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
CVE-2026-8935 CRITICAL Patched 9.8 2026-06-15 The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing it…
CVE-2026-8927 CRITICAL Patched 9.1 2026-07-03 When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between req…
CVE-2026-8926 CRITICAL Patched 9.1 2026-07-03 When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, cur…
CVE-2026-8925 CRITICAL Patched 9.8 2026-07-03 The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same p…
CVE-2026-8924 CRITICAL Patched 9.1 2026-07-03 A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled or…
CVE-2026-8859 CRITICAL Patched 9.9 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest c…
CVE-2026-8838 CRITICAL Patched 9.8 2026-05-18 Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle …
CVE-2026-8836 CRITICAL 9.8 2026-05-18 A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. P…
CVE-2026-8809 CRITICAL 9.8 2026-05-28 The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulne…
CVE-2026-8760 CRITICAL 9.8 2026-05-27 The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplete fix for CVE-2024-1117…
CVE-2026-8732 CRITICAL 9.8 2026-05-29 The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to th…
CVE-2026-8721 CRITICAL 9.8 2026-05-17 Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *, which routes through P…
CVE-2026-8713 CRITICAL 9.1 2026-06-19 The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all …
CVE-2026-8670 CRITICAL Patched 9.6 2026-05-22 Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session IDs (aka Session Replay). This issue affects Avantra:…
CVE-2026-8655 CRITICAL Patched 9.8 2026-06-30 Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is con…
CVE-2026-8644 CRITICAL Patched 9.1 2026-06-01 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
CVE-2026-8635 CRITICAL Patched 9.9 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system command…
CVE-2026-8634 CRITICAL 9.1 2026-05-14 Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a malicious or compromised repository to forward local…
CVE-2026-8633 CRITICAL Patched 9.8 2026-05-26 IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulner…