Search
34,865 CVEs · Critical severity
CVEs (34,865, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 126–150 of 34,865 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85181 | CRITICAL | 9.8 | 2026-09-03 | CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can… | |
| CVE-2026-85183 | CRITICAL | 9.3 | 2026-09-03 | Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim… | |
| CVE-2026-85109 | CRITICAL | 9.8 | 2026-09-03 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing … | |
| CVE-2026-85154 | CRITICAL | 9.8 | 2026-09-03 | WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator… | |
| CVE-2026-85031 | CRITICAL | 9.9 | 2026-09-03 | A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument t… | |
| CVE-2026-80726 | CRITICAL | 9.3 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page Explicitly clear role.inva… | |
| CVE-2026-19117 | CRITICAL | 9.8 | 2026-09-02 | Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects … | |
| CVE-2026-66786 | CRITICAL | 9.1 | 2026-09-02 | A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper va… | |
| CVE-2026-53649 | CRITICAL | Patched | 9.6 | 2026-09-02 | Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a … |
| CVE-2026-20279 | CRITICAL | 9.8 | 2026-09-02 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … | |
| CVE-2026-20274 | CRITICAL | 9.8 | 2026-09-02 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … | |
| CVE-2026-20212 | CRITICAL | 9.8 | 2026-09-02 | A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privilege… | |
| CVE-2026-53611 | CRITICAL | Patched | 9.8 | 2026-09-02 | Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute /… |
| CVE-2026-77009 | CRITICAL | 9.9 | 2026-09-02 | The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user,… | |
| CVE-2026-4357 | CRITICAL | 10.0 | 2026-09-02 | The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for un… | |
| CVE-2025-9314 | CRITICAL | 9.8 | 2026-09-02 | The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component | |
| CVE-2026-73475 | CRITICAL | Patched | 9.1 | 2026-09-02 | Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3. |
| CVE-2026-84803 | CRITICAL | 9.0 | 2026-09-02 | SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. A… | |
| CVE-2026-84795 | CRITICAL | Patched | 9.8 | 2026-09-02 | Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a de… |
| CVE-2026-81286 | CRITICAL | 9.3 | 2026-09-02 | Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions. | |
| CVE-2026-81294 | CRITICAL | 9.8 | 2026-09-02 | Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions. | |
| CVE-2026-78657 | CRITICAL | 9.8 | 2026-09-02 | The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_file… | |
| CVE-2026-9055 | CRITICAL | 9.8 | 2026-09-02 | The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insuf… | |
| CVE-2026-84699 | CRITICAL | Patched | 9.1 | 2026-09-02 | Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local acc… |
| CVE-2026-84352 | CRITICAL | 9.6 | 2026-09-02 | Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML pag… |