Search
9,841 CVEs
CVEs (9,841, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 151–175 of 9,841 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34047 | CRITICAL | Patched | 9.9 | 2026-07-07 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal WebSocket bootstrap routes did not enf… |
| CVE-2026-34048 | CRITICAL | Patched | 9.9 | 2026-07-07 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check … |
| CVE-2026-34038 | CRITICAL | Patched | 9.9 | 2026-07-06 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulne… |
| CVE-2026-48614 | CRITICAL | 9.9 | 2026-07-06 | An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as… | |
| CVE-2026-40141 | CRITICAL | Patched | 9.9 | 2026-07-06 | A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input pa… |
| CVE-2026-45499 | CRITICAL | 9.9 | 2026-07-02 | Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-57100 | CRITICAL | 9.9 | 2026-07-02 | Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-44935 | CRITICAL | Patched | 9.9 | 2026-07-02 | Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 cou… |
| CVE-2026-55115 | CRITICAL | Patched | 9.9 | 2026-07-02 | A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on th… |
| CVE-2026-54402 | CRITICAL | Patched | 9.9 | 2026-07-02 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on… |
| CVE-2026-50747 | CRITICAL | Patched | 9.9 | 2026-07-02 | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to esc… |
| CVE-2026-50748 | CRITICAL | Patched | 9.9 | 2026-07-02 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Comm… |
| CVE-2026-27419 | CRITICAL | 9.9 | 2026-07-02 | Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions. | |
| CVE-2026-50195 | CRITICAL | Patched | 9.9 | 2026-07-01 | containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to vali… |
| CVE-2026-7873 | CRITICAL | Patched | 9.9 | 2026-06-30 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete syst… |
| CVE-2026-57331 | CRITICAL | 9.9 | 2026-06-29 | Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions. | |
| CVE-2026-58053 | CRITICAL | 9.9 | 2026-06-28 | Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured wi… | |
| CVE-2026-52785 | CRITICAL | Patched | 9.9 | 2026-06-26 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject baseline co… |
| CVE-2026-52782 | CRITICAL | Patched | 9.9 | 2026-06-26 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/project_storages/<A_ps_id> vi… |
| CVE-2026-46386 | CRITICAL | Patched | 9.9 | 2026-06-26 | OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as th… |
| CVE-2026-56058 | CRITICAL | 9.9 | 2026-06-26 | Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions. | |
| CVE-2026-56059 | CRITICAL | 9.9 | 2026-06-26 | Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions. | |
| CVE-2026-56027 | CRITICAL | 9.9 | 2026-06-26 | Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions. | |
| CVE-2026-54823 | CRITICAL | 9.9 | 2026-06-25 | Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions. | |
| CVE-2026-55454 | CRITICAL | Patched | 9.9 | 2026-06-24 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has no authentication by def… |