Search
34,865 CVEs · Critical severity
CVEs (34,865, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 151–175 of 34,865 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84353 | CRITICAL | 9.6 | 2026-09-02 | Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code … | |
| CVE-2026-84354 | CRITICAL | Patched | 9.6 | 2026-09-02 | Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the … |
| CVE-2026-84333 | CRITICAL | 9.6 | 2026-09-02 | Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page… | |
| CVE-2026-84324 | CRITICAL | Patched | 9.0 | 2026-09-02 | Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromi… |
| CVE-2026-84325 | CRITICAL | Patched | 9.8 | 2026-09-02 | Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictio… |
| CVE-2026-84479 | CRITICAL | 9.1 | 2026-09-01 | WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoM… | |
| CVE-2026-84480 | CRITICAL | 9.8 | 2026-09-01 | WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefi… | |
| CVE-2026-84637 | CRITICAL | Patched | 9.8 | 2026-09-01 | Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment… |
| CVE-2026-84639 | CRITICAL | Patched | 9.1 | 2026-09-01 | Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and T… |
| CVE-2026-84372 | CRITICAL | Patched | 9.8 | 2026-09-01 | Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replicatio… |
| CVE-2026-83548 | CRITICAL | Patched | 10.0 | 2026-09-01 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker c… |
| CVE-2026-75604 | CRITICAL | Patched | 9.0 | 2026-09-01 | Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without C… |
| CVE-2023-54391 | CRITICAL | Patched | 9.8 | 2026-09-01 | Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers… |
| CVE-2026-73749 | CRITICAL | Patched | 9.8 | 2026-09-01 | Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulne… |
| CVE-2026-76658 | CRITICAL | Patched | 10.0 | 2026-09-01 | A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to… |
| CVE-2026-76657 | CRITICAL | Patched | 10.0 | 2026-09-01 | Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing aut… |
| CVE-2026-73700 | CRITICAL | Patched | 9.0 | 2026-09-01 | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-s… |
| CVE-2026-73701 | CRITICAL | Patched | 9.0 | 2026-09-01 | An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain precond… |
| CVE-2026-19766 | CRITICAL | Patched | 9.6 | 2026-09-01 | An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated a… |
| CVE-2026-52111 | CRITICAL | 9.8 | 2026-09-01 | An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes authTokenKey | |
| CVE-2026-19593 | CRITICAL | 9.8 | 2026-09-01 | OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a reposito… | |
| CVE-2026-51934 | CRITICAL | 9.8 | 2026-09-01 | Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co., Ltd. Tenda A18 v.15.13.07.09 allows a remote attacker to execute arbitrary code via the fromSetCmdl… | |
| CVE-2026-79687 | CRITICAL | 9.0 | 2026-09-01 | Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this v… | |
| CVE-2026-51769 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to restart the cloud update check work… | |
| CVE-2026-51770 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS sett… |