Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

32,629 CVEs · Critical severity

CVEs (32,629, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 126–150 of 32,629 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-8181 CRITICAL 9.8 2026-05-14 The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to …
CVE-2026-8175 CRITICAL Patched 9.8 2026-05-27 IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Tr…
CVE-2026-8153 CRITICAL 9.8 2026-05-08 OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthenticated attacker to craft commands that will execut…
CVE-2026-8094 CRITICAL Patched 9.8 2026-05-07 Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.
CVE-2026-8091 CRITICAL Patched 9.8 2026-05-07 Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10…
CVE-2026-8043 CRITICAL Patched 9.6 2026-05-12 External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a…
CVE-2026-8037 CRITICAL Patched 9.6 2026-06-04 OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster…
CVE-2026-8034 CRITICAL Patched 9.8 2026-05-07 A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by ex…
CVE-2026-8025 CRITICAL 9.8 2026-06-09 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. CBS Platform allows SQL Injection. …
CVE-2026-8024 CRITICAL 9.8 2026-06-18 A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.
CVE-2026-7910 CRITICAL Patched 9.6 2026-05-06 Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HT…
CVE-2026-7908 CRITICAL Patched 9.6 2026-05-06 Use after free in Fullscreen in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium se…
CVE-2026-7891 CRITICAL 9.1 2026-05-07 A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not adequately describe the special behavior of the System.…
CVE-2026-7876 CRITICAL Patched 9.1 2026-05-27 IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage of this vulnerability t…
CVE-2026-7874 CRITICAL Patched 9.1 2026-06-30 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak and reversible key derivation mechanism for encrypt…
CVE-2026-7873 CRITICAL Patched 9.9 2026-06-30 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete syst…
CVE-2026-7871 CRITICAL Patched 9.8 2026-06-30 IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system …
CVE-2026-7858 CRITICAL 9.8 2026-06-01 A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CA…
CVE-2026-7854 CRITICAL 9.8 2026-05-05 A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function url_rule_asp of the file /url_rule.asp of the compon…
CVE-2026-7853 CRITICAL 9.8 2026-05-05 A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulation …
CVE-2026-7852 CRITICAL Patched 9.8 2026-06-11 Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclusion. This issue affects LimRAD NAC: before 5.5.7.3.9.
CVE-2026-7840 CRITICAL Patched 9.8 2026-07-01 UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server. The functions wi_senderr() and wi_replyhdr() in repeater/web…
CVE-2026-7839 CRITICAL Patched 9.1 2026-07-01 UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repeater/webgui/settings.c:197, when settings2.txt is abs…
CVE-2026-7834 CRITICAL 9.8 2026-05-05 A security vulnerability has been detected in EFM ipTIME NAS1dual 1.5.24. This issue affects the function get_csrf_whites of the file /cgi/advanced/misc_main.cgi. Such mani…
CVE-2026-7823 CRITICAL 9.8 2026-05-05 A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of …