Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

34,865 CVEs · Critical severity

CVEs (34,865, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 201–225 of 34,865 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-84639 CRITICAL Patched 9.1 2026-09-01 Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and T…
CVE-2026-84637 CRITICAL Patched 9.8 2026-09-01 Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment…
CVE-2026-8457 CRITICAL 9.8 2026-08-02 The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple logi…
CVE-2026-8452 CRITICAL Patched 9.8 2026-06-30 Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a G…
CVE-2026-8450 CRITICAL Patched 9.1 2026-05-27 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form inter…
CVE-2026-84480 CRITICAL 9.8 2026-09-01 WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefi…
CVE-2026-84479 CRITICAL 9.1 2026-09-01 WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoM…
CVE-2026-8445 CRITICAL Patched 9.8 2026-08-23 justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Mar&hellip;
CVE-2026-84372 CRITICAL Patched 9.8 2026-09-01 Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replicatio&hellip;
CVE-2026-84354 CRITICAL Patched 9.6 2026-09-02 Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the &hellip;
CVE-2026-84353 CRITICAL 9.6 2026-09-02 Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code &hellip;
CVE-2026-84352 CRITICAL 9.6 2026-09-02 Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML pag&hellip;
CVE-2026-84333 CRITICAL 9.6 2026-09-02 Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page&hellip;
CVE-2026-84325 CRITICAL Patched 9.8 2026-09-02 Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictio&hellip;
CVE-2026-84324 CRITICAL Patched 9.0 2026-09-02 Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromi&hellip;
CVE-2026-84238 CRITICAL 9.8 2026-09-03 Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.
CVE-2026-84200 CRITICAL Patched 9.0 2026-09-01 Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive &hellip;
CVE-2026-84143 CRITICAL Patched 9.8 2026-09-01 Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another secur&hellip;
CVE-2026-84142 CRITICAL Patched 9.8 2026-09-01 Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enoug&hellip;
CVE-2026-84141 CRITICAL Patched 9.8 2026-09-01 Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84140 CRITICAL Patched 9.8 2026-09-01 Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84135 CRITICAL Patched 9.8 2026-09-01 Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.
CVE-2026-84134 CRITICAL Patched 9.8 2026-09-01 Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84133 CRITICAL Patched 9.8 2026-09-01 Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84129 CRITICAL Patched 9.8 2026-09-01 Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.