Search
478 CVEs · Critical severity
CVEs (478)
Showing 1–25 of 478
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-20096 | CRITICAL | 9.8 | 2026-07-21 | Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by… | |
| CVE-2024-23564 | CRITICAL | 9.1 | 2026-07-17 | HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to th… | |
| CVE-2024-51311 | CRITICAL | 9.8 | 2026-07-20 | The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList. | |
| CVE-2024-51312 | CRITICAL | 9.8 | 2026-07-20 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg. | |
| CVE-2024-51313 | CRITICAL | 9.8 | 2026-07-20 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg. | |
| CVE-2024-51314 | CRITICAL | 9.8 | 2026-07-20 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg. | |
| CVE-2024-51315 | CRITICAL | 9.8 | 2026-07-20 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName | |
| CVE-2024-58354 | CRITICAL | 9.9 | 2026-07-23 | cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_req… | |
| CVE-2025-51677 | CRITICAL | 9.1 | 2026-07-17 | An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can lead to unexpected behavior. | |
| CVE-2025-66390 | CRITICAL | 9.8 | 2026-07-21 | In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the re… | |
| CVE-2025-71389 | CRITICAL | Patched | 10.0 | 2026-07-23 | Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) req… |
| CVE-2026-12692 | CRITICAL | Patched | 9.8 | 2026-07-17 | Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0… |
| CVE-2026-12693 | CRITICAL | Patched | 9.4 | 2026-07-17 | Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. … |
| CVE-2026-12694 | CRITICAL | Patched | 9.1 | 2026-07-17 | Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterpri… |
| CVE-2026-12701 | CRITICAL | 9.0 | 2026-07-20 | A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directo… | |
| CVE-2026-13147 | CRITICAL | Patched | 9.1 | 2026-07-20 | The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue … |
| CVE-2026-13439 | CRITICAL | 9.8 | 2026-07-21 | The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 Th… | |
| CVE-2026-13446 | CRITICAL | Patched | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound c… |
| CVE-2026-14282 | CRITICAL | 9.8 | 2026-07-23 | The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in… | |
| CVE-2026-14956 | CRITICAL | 9.8 | 2026-07-17 | The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds… | |
| CVE-2026-15011 | CRITICAL | 9.8 | 2026-07-23 | The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due … | |
| CVE-2026-15015 | CRITICAL | 9.8 | 2026-07-23 | The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugi… | |
| CVE-2026-15091 | CRITICAL | 9.3 | 2026-07-17 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation. | |
| CVE-2026-15899 | CRITICAL | 9.6 | 2026-07-20 | Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (… | |
| CVE-2026-15900 | CRITICAL | 9.6 | 2026-07-20 | Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromi… |