Search
34,854 CVEs · Critical severity
CVEs (34,854, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 126–150 of 34,854 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-53611 | CRITICAL | Patched | 9.8 | 2026-09-02 | Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute /… |
| CVE-2026-77009 | CRITICAL | 9.9 | 2026-09-02 | The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user,… | |
| CVE-2026-4357 | CRITICAL | 10.0 | 2026-09-02 | The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for un… | |
| CVE-2025-9314 | CRITICAL | 9.8 | 2026-09-02 | The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component | |
| CVE-2026-73475 | CRITICAL | 9.1 | 2026-09-02 | Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3. | |
| CVE-2026-84803 | CRITICAL | 9.0 | 2026-09-02 | SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. A… | |
| CVE-2026-84795 | CRITICAL | Patched | 9.8 | 2026-09-02 | Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a de… |
| CVE-2026-81294 | CRITICAL | 9.8 | 2026-09-02 | Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions. | |
| CVE-2026-81286 | CRITICAL | 9.3 | 2026-09-02 | Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions. | |
| CVE-2026-78657 | CRITICAL | 9.8 | 2026-09-02 | The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_file… | |
| CVE-2026-9055 | CRITICAL | 9.8 | 2026-09-02 | The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insuf… | |
| CVE-2026-84699 | CRITICAL | Patched | 9.1 | 2026-09-02 | Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local acc… |
| CVE-2026-84354 | CRITICAL | Patched | 9.6 | 2026-09-02 | Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the … |
| CVE-2026-84353 | CRITICAL | 9.6 | 2026-09-02 | Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code … | |
| CVE-2026-84352 | CRITICAL | 9.6 | 2026-09-02 | Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML pag… | |
| CVE-2026-84333 | CRITICAL | 9.6 | 2026-09-02 | Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page… | |
| CVE-2026-84325 | CRITICAL | Patched | 9.8 | 2026-09-02 | Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictio… |
| CVE-2026-84324 | CRITICAL | Patched | 9.0 | 2026-09-02 | Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromi… |
| CVE-2026-84480 | CRITICAL | 9.8 | 2026-09-01 | WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefi… | |
| CVE-2026-84479 | CRITICAL | 9.1 | 2026-09-01 | WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoM… | |
| CVE-2026-84639 | CRITICAL | Patched | 9.1 | 2026-09-01 | Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and T… |
| CVE-2026-84637 | CRITICAL | Patched | 9.8 | 2026-09-01 | Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment… |
| CVE-2026-84372 | CRITICAL | Patched | 9.8 | 2026-09-01 | Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replicatio… |
| CVE-2026-83548 | CRITICAL | Patched | 10.0 | 2026-09-01 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker c… |
| CVE-2026-75604 | CRITICAL | Patched | 9.0 | 2026-09-01 | Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without C… |