Search
34,854 CVEs · Critical severity
CVEs (34,854, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 101–125 of 34,854 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-85047 | CRITICAL | 9.6 | 2026-09-03 | Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside… | |
| CVE-2026-85043 | CRITICAL | 9.1 | 2026-09-03 | Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium … | |
| CVE-2026-85042 | CRITICAL | 9.6 | 2026-09-03 | Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromiu… | |
| CVE-2026-85394 | CRITICAL | 9.1 | 2026-09-03 | python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attacker… | |
| CVE-2026-85391 | CRITICAL | 9.8 | 2026-09-03 | Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attack… | |
| CVE-2026-82526 | CRITICAL | 9.8 | 2026-09-03 | R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name pa… | |
| CVE-2026-58400 | CRITICAL | Patched | 9.1 | 2026-09-03 | GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is con… |
| CVE-2026-84834 | CRITICAL | 9.8 | 2026-09-03 | Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions. | |
| CVE-2026-84814 | CRITICAL | 9.8 | 2026-09-03 | Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions. | |
| CVE-2026-84813 | CRITICAL | 9.3 | 2026-09-03 | Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions. | |
| CVE-2026-84768 | CRITICAL | 9.3 | 2026-09-03 | Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions. | |
| CVE-2026-84753 | CRITICAL | 9.8 | 2026-09-03 | Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. | |
| CVE-2026-84238 | CRITICAL | 9.8 | 2026-09-03 | Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions. | |
| CVE-2026-85183 | CRITICAL | 9.3 | 2026-09-03 | Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim… | |
| CVE-2026-85181 | CRITICAL | 9.8 | 2026-09-03 | CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can… | |
| CVE-2026-85109 | CRITICAL | 9.8 | 2026-09-03 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing … | |
| CVE-2026-85154 | CRITICAL | 9.8 | 2026-09-03 | WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator… | |
| CVE-2026-85031 | CRITICAL | 9.9 | 2026-09-03 | A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument t… | |
| CVE-2026-80726 | CRITICAL | 9.3 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page Explicitly clear role.inva… | |
| CVE-2026-19117 | CRITICAL | 9.8 | 2026-09-02 | Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects … | |
| CVE-2026-66786 | CRITICAL | 9.1 | 2026-09-02 | A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper va… | |
| CVE-2026-53649 | CRITICAL | Patched | 9.6 | 2026-09-02 | Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a … |
| CVE-2026-20279 | CRITICAL | 9.8 | 2026-09-02 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … | |
| CVE-2026-20274 | CRITICAL | 9.8 | 2026-09-02 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … | |
| CVE-2026-20212 | CRITICAL | 9.8 | 2026-09-02 | A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privilege… |