Search
32,636 CVEs · Critical severity
CVEs (32,636, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 32,636 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39305 | CRITICAL | Patched | 9.0 | 2026-04-07 | PraisonAI is a multi-agent teams system. Prior to 1.5.113, the Action Orchestrator feature contains a Path Traversal vulnerability that allows an attacker (or compromised a… |
| CVE-2026-34989 | CRITICAL | Patched | 9.0 | 2026-04-06 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 31.0.0.0, the applica… |
| CVE-2026-28798 | CRITICAL | Patched | 9.0 | 2026-04-03 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a proxy endpoint (/v1/sys/proxy) exposed by ZimaOS's … |
| CVE-2026-35216 | CRITICAL | Patched | 9.0 | 2026-04-03 | Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by trigger… |
| CVE-2026-34448 | CRITICAL | Patched | 9.0 | 2026-03-31 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS … |
| CVE-2026-30282 | CRITICAL | 9.0 | 2026-03-31 | An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internal files via the file import proce… | |
| CVE-2026-33749 | CRITICAL | Patched | 9.0 | 2026-03-25 | n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, an authenticated user with permission to create or modify workflows coul… |
| CVE-2026-32519 | CRITICAL | 9.0 | 2026-03-25 | Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affects Bit SMTP: from n/a through <= 1.2.2. | |
| CVE-2025-32991 | CRITICAL | Patched | 9.0 | 2026-03-25 | In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution. |
| CVE-2025-33244 | CRITICAL | 9.0 | 2026-03-24 | NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data. This vulnerability affects environments that … | |
| CVE-2026-33066 | CRITICAL | Patched | 9.0 | 2026-03-20 | SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREADME function uses lute.New() without calling SetSanitize(true), allowing… |
| CVE-2026-33067 | CRITICAL | Patched | 9.0 | 2026-03-20 | SiYuan is a personal knowledge management system. Versions 3.6.0 and below render package metadata fields (displayName, description) using template literals without HTML es… |
| CVE-2026-32891 | CRITICAL | Patched | 9.0 | 2026-03-20 | Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and below contain a stored XS… |
| CVE-2026-32751 | CRITICAL | Patched | 9.0 | 2026-03-19 | SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the mobile file tree (MobileFiles.ts) renders notebook names via innerHTML without HTML escap… |
| CVE-2026-27540 | CRITICAL | 9.0 | 2026-03-19 | Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using M… | |
| CVE-2026-32703 | CRITICAL | Patched | 9.0 | 2026-03-18 | OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories module did not properly esca… |
| CVE-2026-3564 | CRITICAL | 9.0 | 2026-03-17 | A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized acces… | |
| CVE-2026-32635 | CRITICAL | Patched | 9.0 | 2026-03-16 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-next.3, 21.2.4, 20.3.18,… |
| CVE-2023-27573 | CRITICAL | Patched | 9.0 | 2026-03-11 | netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcdef01234567 value for SU… |
| CVE-2026-27825 | CRITICAL | Patched | 9.0 | 2026-03-10 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, the `confluence_download_attachment` MCP tool … |
| CVE-2026-30862 | CRITICAL | Patched | 9.0 | 2026-03-10 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table Widget (TableWidgetV2).… |
| CVE-2025-59542 | CRITICAL | Patched | 9.0 | 2026-03-06 | Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the co… |
| CVE-2025-59543 | CRITICAL | Patched | 9.0 | 2026-03-06 | Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the co… |
| CVE-2025-55208 | CRITICAL | Patched | 9.0 | 2026-03-05 | Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `Social Networks`. Through it, a low-privilege user ca… |
| CVE-2026-27984 | CRITICAL | 9.0 | 2026-03-05 | Improper Control of Generation of Code ('Code Injection') vulnerability in Marketing Fire Widget Options widget-options allows Code Injection.This issue affects Widget Opti… |