Search
34,865 CVEs · Critical severity
CVEs (34,865, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 126–150 of 34,865 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33749 | CRITICAL | Patched | 9.0 | 2026-03-25 | n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, an authenticated user with permission to create or modify workflows coul… |
| CVE-2026-32519 | CRITICAL | 9.0 | 2026-03-25 | Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affects Bit SMTP: from n/a through <= 1.2.2. | |
| CVE-2025-32991 | CRITICAL | Patched | 9.0 | 2026-03-25 | In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution. |
| CVE-2025-33244 | CRITICAL | 9.0 | 2026-03-24 | NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data. This vulnerability affects environments that … | |
| CVE-2026-33066 | CRITICAL | Patched | 9.0 | 2026-03-20 | SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREADME function uses lute.New() without calling SetSanitize(true), allowing… |
| CVE-2026-33067 | CRITICAL | Patched | 9.0 | 2026-03-20 | SiYuan is a personal knowledge management system. Versions 3.6.0 and below render package metadata fields (displayName, description) using template literals without HTML es… |
| CVE-2026-32891 | CRITICAL | Patched | 9.0 | 2026-03-20 | Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and below contain a stored XS… |
| CVE-2026-32751 | CRITICAL | Patched | 9.0 | 2026-03-19 | SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the mobile file tree (MobileFiles.ts) renders notebook names via innerHTML without HTML escap… |
| CVE-2026-27540 | CRITICAL | 9.0 | 2026-03-19 | Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using M… | |
| CVE-2026-32703 | CRITICAL | Patched | 9.0 | 2026-03-18 | OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories module did not properly esca… |
| CVE-2026-3564 | CRITICAL | 9.0 | 2026-03-17 | A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized acces… | |
| CVE-2026-32635 | CRITICAL | Patched | 9.0 | 2026-03-16 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-next.3, 21.2.4, 20.3.18,… |
| CVE-2023-27573 | CRITICAL | Patched | 9.0 | 2026-03-11 | netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcdef01234567 value for SU… |
| CVE-2026-27825 | CRITICAL | Patched | 9.0 | 2026-03-10 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, the `confluence_download_attachment` MCP tool … |
| CVE-2026-30862 | CRITICAL | Patched | 9.0 | 2026-03-10 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table Widget (TableWidgetV2).… |
| CVE-2025-59542 | CRITICAL | Patched | 9.0 | 2026-03-06 | Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the co… |
| CVE-2025-59543 | CRITICAL | Patched | 9.0 | 2026-03-06 | Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the co… |
| CVE-2025-55208 | CRITICAL | Patched | 9.0 | 2026-03-05 | Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `Social Networks`. Through it, a low-privilege user ca… |
| CVE-2026-27984 | CRITICAL | 9.0 | 2026-03-05 | Improper Control of Generation of Code ('Code Injection') vulnerability in Marketing Fire Widget Options widget-options allows Code Injection.This issue affects Widget Opti… | |
| CVE-2026-27384 | CRITICAL | 9.0 | 2026-03-05 | Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Accessing Functionality Not Properly Constrained by ACLs.T… | |
| CVE-2025-66024 | CRITICAL | Patched | 9.0 | 2026-03-04 | The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15.7 are vulnerable to Stored Cros… |
| CVE-2026-24663 | CRITICAL | Patched | 9.0 | 2026-02-27 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by … |
| CVE-2026-27493 | CRITICAL | Patched | 9.0 | 2026-02-25 | n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expression injection vulnerability existed in n8n's Form n… |
| CVE-2026-27822 | CRITICAL | 9.0 | 2026-02-25 | RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.83, a Stored Cross-Site Scripting (XSS) vulnerability in the RustFS Console allows… | |
| CVE-2026-0573 | CRITICAL | Patched | 9.0 | 2026-02-18 | An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects to leak sensitive authorization tokens. The repositor… |