Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,217 CVEs

CVEs (30,217, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 101–125 of 30,217 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-17061 CRITICAL 10.0 2026-08-11 A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.
CVE-2026-48056 CRITICAL 10.0 2026-08-11 Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the  run…
CVE-2026-58115 CRITICAL 10.0 2026-08-11 A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devic&hellip;
CVE-2026-58231 CRITICAL 10.0 2026-08-11 SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient va&hellip;
CVE-2026-72898 CRITICAL Patched 10.0 2026-08-10 Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metaba&hellip;
CVE-2026-72899 CRITICAL 10.0 2026-08-10 Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.
CVE-2026-66915 NONE &mdash; 2026-08-10 Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the c&hellip;
CVE-2026-65667 CRITICAL 10.0 2026-08-07 Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-63508 CRITICAL 10.0 2026-08-07 Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56162 CRITICAL 10.0 2026-08-07 Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-14812 CRITICAL 10.0 2026-08-06 The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote cod&hellip;
CVE-2026-11976 CRITICAL 10.0 2026-08-06 The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version Monster&hellip;
CVE-2026-66665 CRITICAL 10.0 2026-08-06 Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
CVE-2026-65553 CRITICAL 10.0 2026-08-06 Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.
CVE-2026-5430 CRITICAL Patched 10.0 2026-08-06 The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an u&hellip;
CVE-2026-48168 CRITICAL Patched 10.0 2026-08-05 PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an att&hellip;
CVE-2026-16940 CRITICAL Patched 10.0 2026-08-05 The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the&hellip;
CVE-2026-64633 NONE &mdash; 2026-08-04 A vulnerability allowing remote unauthenticated code execution on the agent host.
CVE-2026-48323 CRITICAL Patched 10.0 2026-08-03 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execu&hellip;
CVE-2026-48330 CRITICAL Patched 10.0 2026-08-03 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbit&hellip;
CVE-2026-48331 CRITICAL Patched 10.0 2026-08-03 Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does no&hellip;
CVE-2026-69083 CRITICAL 10.0 2026-08-03 SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tok&hellip;
CVE-2026-69084 CRITICAL Patched 10.0 2026-08-03 SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle wi&hellip;
CVE-2026-69085 CRITICAL 10.0 2026-08-03 SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly i&hellip;
CVE-2026-33591 NONE &mdash; 2026-08-03 A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retr&hellip;