Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

1,528 CVEs · Critical severity

CVEs (1,528, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 126–150 of 1,528 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-85183 CRITICAL 9.3 2026-09-03 Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim…
CVE-2026-85181 CRITICAL 9.8 2026-09-03 CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can…
CVE-2026-85109 CRITICAL 9.8 2026-09-03 A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing …
CVE-2026-85154 CRITICAL 9.8 2026-09-03 WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator…
CVE-2026-85031 CRITICAL 9.9 2026-09-03 A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument t…
CVE-2026-80726 CRITICAL 9.3 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page Explicitly clear role.inva…
CVE-2026-19117 CRITICAL 9.8 2026-09-02 Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects …
CVE-2026-66786 CRITICAL 9.1 2026-09-02 A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper va…
CVE-2026-53649 CRITICAL Patched 9.6 2026-09-02 Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a …
CVE-2026-20279 CRITICAL 9.8 2026-09-02 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security …
CVE-2026-20274 CRITICAL 9.8 2026-09-02 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security …
CVE-2026-20212 CRITICAL 9.8 2026-09-02 A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privilege…
CVE-2026-53611 CRITICAL Patched 9.8 2026-09-02 Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute /…
CVE-2026-77009 CRITICAL 9.9 2026-09-02 The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user,…
CVE-2026-4357 CRITICAL 10.0 2026-09-02 The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for un…
CVE-2025-9314 CRITICAL 9.8 2026-09-02 The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component
CVE-2026-73475 CRITICAL Patched 9.1 2026-09-02 Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.
CVE-2026-84803 CRITICAL 9.0 2026-09-02 SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. A…
CVE-2026-84795 CRITICAL Patched 9.8 2026-09-02 Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a de…
CVE-2026-81294 CRITICAL 9.8 2026-09-02 Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
CVE-2026-81286 CRITICAL 9.3 2026-09-02 Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.
CVE-2026-78657 CRITICAL 9.8 2026-09-02 The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_file&hellip;
CVE-2026-9055 CRITICAL 9.8 2026-09-02 The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insuf&hellip;
CVE-2026-84699 CRITICAL Patched 9.1 2026-09-02 Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local acc&hellip;
CVE-2026-84354 CRITICAL Patched 9.6 2026-09-02 Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the &hellip;