Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

9,841 CVEs

CVEs (9,841, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 151–175 of 9,841 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-34047 CRITICAL Patched 9.9 2026-07-07 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal WebSocket bootstrap routes did not enf…
CVE-2026-34048 CRITICAL Patched 9.9 2026-07-07 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check …
CVE-2026-34038 CRITICAL Patched 9.9 2026-07-06 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulne…
CVE-2026-48614 CRITICAL 9.9 2026-07-06 An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as…
CVE-2026-40141 CRITICAL Patched 9.9 2026-07-06 A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input pa…
CVE-2026-45499 CRITICAL 9.9 2026-07-02 Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
CVE-2026-57100 CRITICAL 9.9 2026-07-02 Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
CVE-2026-44935 CRITICAL Patched 9.9 2026-07-02 Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 cou…
CVE-2026-55115 CRITICAL Patched 9.9 2026-07-02 A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on th…
CVE-2026-54402 CRITICAL Patched 9.9 2026-07-02 A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on…
CVE-2026-50747 CRITICAL Patched 9.9 2026-07-02 A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to esc…
CVE-2026-50748 CRITICAL Patched 9.9 2026-07-02 A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Comm…
CVE-2026-27419 CRITICAL 9.9 2026-07-02 Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
CVE-2026-50195 CRITICAL Patched 9.9 2026-07-01 containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to vali&hellip;
CVE-2026-7873 CRITICAL Patched 9.9 2026-06-30 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete syst&hellip;
CVE-2026-57331 CRITICAL 9.9 2026-06-29 Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
CVE-2026-58053 CRITICAL 9.9 2026-06-28 Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured wi&hellip;
CVE-2026-52785 CRITICAL Patched 9.9 2026-06-26 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject baseline co&hellip;
CVE-2026-52782 CRITICAL Patched 9.9 2026-06-26 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/project_storages/<A_ps_id> vi&hellip;
CVE-2026-46386 CRITICAL Patched 9.9 2026-06-26 OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as th&hellip;
CVE-2026-56058 CRITICAL 9.9 2026-06-26 Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.
CVE-2026-56059 CRITICAL 9.9 2026-06-26 Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
CVE-2026-56027 CRITICAL 9.9 2026-06-26 Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
CVE-2026-54823 CRITICAL 9.9 2026-06-25 Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.
CVE-2026-55454 CRITICAL Patched 9.9 2026-06-24 Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has no authentication by def&hellip;