Search
34,865 CVEs · Critical severity
CVEs (34,865, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 176–200 of 34,865 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85148 | CRITICAL | 9.8 | 2026-09-04 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely … | |
| CVE-2026-85146 | CRITICAL | 9.8 | 2026-09-04 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account creden… | |
| CVE-2026-8511 | CRITICAL | Patched | 9.6 | 2026-05-14 | Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security … |
| CVE-2026-85109 | CRITICAL | 9.8 | 2026-09-03 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing … | |
| CVE-2026-85085 | CRITICAL | Patched | 9.6 | 2026-09-04 | The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to com… |
| CVE-2026-8507 | CRITICAL | 9.8 | 2026-05-17 | Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attrib… | |
| CVE-2026-85061 | CRITICAL | Patched | 10.0 | 2026-09-03 | MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap… |
| CVE-2026-85050 | CRITICAL | 9.6 | 2026-09-03 | Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTM… | |
| CVE-2026-8505 | CRITICAL | Patched | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The … |
| CVE-2026-85047 | CRITICAL | 9.6 | 2026-09-03 | Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside… | |
| CVE-2026-85043 | CRITICAL | 9.1 | 2026-09-03 | Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium … | |
| CVE-2026-85042 | CRITICAL | 9.6 | 2026-09-03 | Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromiu… | |
| CVE-2026-85031 | CRITICAL | 9.9 | 2026-09-03 | A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument t… | |
| CVE-2026-8500 | CRITICAL | 9.8 | 2026-05-13 | Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command. The user p… | |
| CVE-2026-8495 | CRITICAL | Patched | 9.8 | 2026-05-19 | Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0.0.0 before 4.0.15. |
| CVE-2026-84834 | CRITICAL | 9.8 | 2026-09-03 | Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions. | |
| CVE-2026-84814 | CRITICAL | 9.8 | 2026-09-03 | Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions. | |
| CVE-2026-84813 | CRITICAL | 9.3 | 2026-09-03 | Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions. | |
| CVE-2026-8481 | CRITICAL | Patched | 9.9 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint ac… |
| CVE-2026-84803 | CRITICAL | 9.0 | 2026-09-02 | SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. A… | |
| CVE-2026-84795 | CRITICAL | Patched | 9.8 | 2026-09-02 | Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a de… |
| CVE-2026-84768 | CRITICAL | 9.3 | 2026-09-03 | Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions. | |
| CVE-2026-8476 | CRITICAL | Patched | 9.9 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's uns… |
| CVE-2026-84753 | CRITICAL | 9.8 | 2026-09-03 | Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. | |
| CVE-2026-84699 | CRITICAL | Patched | 9.1 | 2026-09-02 | Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local acc… |