Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

34,865 CVEs · Critical severity

CVEs (34,865, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 176–200 of 34,865 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-85148 CRITICAL 9.8 2026-09-04 SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely …
CVE-2026-85146 CRITICAL 9.8 2026-09-04 SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account creden…
CVE-2026-8511 CRITICAL Patched 9.6 2026-05-14 Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security …
CVE-2026-85109 CRITICAL 9.8 2026-09-03 A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing …
CVE-2026-85085 CRITICAL Patched 9.6 2026-09-04 The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to com…
CVE-2026-8507 CRITICAL 9.8 2026-05-17 Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attrib…
CVE-2026-85061 CRITICAL Patched 10.0 2026-09-03 MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap…
CVE-2026-85050 CRITICAL 9.6 2026-09-03 Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTM…
CVE-2026-8505 CRITICAL Patched 9.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The …
CVE-2026-85047 CRITICAL 9.6 2026-09-03 Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside…
CVE-2026-85043 CRITICAL 9.1 2026-09-03 Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium …
CVE-2026-85042 CRITICAL 9.6 2026-09-03 Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromiu…
CVE-2026-85031 CRITICAL 9.9 2026-09-03 A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument t…
CVE-2026-8500 CRITICAL 9.8 2026-05-13 Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command. The user p…
CVE-2026-8495 CRITICAL Patched 9.8 2026-05-19 Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0.0.0 before 4.0.15.
CVE-2026-84834 CRITICAL 9.8 2026-09-03 Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
CVE-2026-84814 CRITICAL 9.8 2026-09-03 Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
CVE-2026-84813 CRITICAL 9.3 2026-09-03 Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.
CVE-2026-8481 CRITICAL Patched 9.9 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint ac&hellip;
CVE-2026-84803 CRITICAL 9.0 2026-09-02 SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. A&hellip;
CVE-2026-84795 CRITICAL Patched 9.8 2026-09-02 Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a de&hellip;
CVE-2026-84768 CRITICAL 9.3 2026-09-03 Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.
CVE-2026-8476 CRITICAL Patched 9.9 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's uns&hellip;
CVE-2026-84753 CRITICAL 9.8 2026-09-03 Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
CVE-2026-84699 CRITICAL Patched 9.1 2026-09-02 Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local acc&hellip;