Search
34,969 CVEs · Critical severity
CVEs (34,969, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 34,969 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-73299 | CRITICAL | Patched | 10.0 | 2026-08-12 | Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies… |
| CVE-2026-45618 | CRITICAL | 10.0 | 2026-08-11 | LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 pa… | |
| CVE-2026-71398 | CRITICAL | Patched | 10.0 | 2026-08-11 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An at… |
| CVE-2026-27302 | CRITICAL | Patched | 10.0 | 2026-08-11 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An at… |
| CVE-2026-48362 | CRITICAL | 10.0 | 2026-08-11 | ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code ex… | |
| CVE-2026-17061 | CRITICAL | 10.0 | 2026-08-11 | A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution. | |
| CVE-2026-48056 | CRITICAL | 10.0 | 2026-08-11 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the run… | |
| CVE-2026-58115 | CRITICAL | 10.0 | 2026-08-11 | A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devic… | |
| CVE-2026-58231 | CRITICAL | 10.0 | 2026-08-11 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient va… | |
| CVE-2026-72898 | CRITICAL | Patched | 10.0 | 2026-08-10 | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metaba… |
| CVE-2026-72899 | CRITICAL | 10.0 | 2026-08-10 | Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter. | |
| CVE-2026-65667 | CRITICAL | 10.0 | 2026-08-07 | Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-63508 | CRITICAL | 10.0 | 2026-08-07 | Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-56162 | CRITICAL | 10.0 | 2026-08-07 | Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-14812 | CRITICAL | 10.0 | 2026-08-06 | The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote cod… | |
| CVE-2026-11976 | CRITICAL | 10.0 | 2026-08-06 | The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version Monster… | |
| CVE-2026-66665 | CRITICAL | 10.0 | 2026-08-06 | Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions. | |
| CVE-2026-65553 | CRITICAL | 10.0 | 2026-08-06 | Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions. | |
| CVE-2026-5430 | CRITICAL | Patched | 10.0 | 2026-08-06 | The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an u… |
| CVE-2026-48168 | CRITICAL | Patched | 10.0 | 2026-08-05 | PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an att… |
| CVE-2026-16940 | CRITICAL | Patched | 10.0 | 2026-08-05 | The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the… |
| CVE-2026-48323 | CRITICAL | Patched | 10.0 | 2026-08-03 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execu… |
| CVE-2026-48330 | CRITICAL | Patched | 10.0 | 2026-08-03 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbit… |
| CVE-2026-48331 | CRITICAL | Patched | 10.0 | 2026-08-03 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does no… |
| CVE-2026-69083 | CRITICAL | 10.0 | 2026-08-03 | SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tok… |