Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

478 CVEs · Critical severity

CVEs (478)

Showing 1–25 of 478

CVE ID Severity Patch CVSS Published Description
CVE-2016-20096 CRITICAL 9.8 2026-07-21 Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by…
CVE-2024-23564 CRITICAL 9.1 2026-07-17 HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to th…
CVE-2024-51311 CRITICAL 9.8 2026-07-20 The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList.
CVE-2024-51312 CRITICAL 9.8 2026-07-20 The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg.
CVE-2024-51313 CRITICAL 9.8 2026-07-20 The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg.
CVE-2024-51314 CRITICAL 9.8 2026-07-20 The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg.
CVE-2024-51315 CRITICAL 9.8 2026-07-20 The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName
CVE-2024-58354 CRITICAL 9.9 2026-07-23 cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_req…
CVE-2025-51677 CRITICAL 9.1 2026-07-17 An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can lead to unexpected behavior.
CVE-2025-66390 CRITICAL 9.8 2026-07-21 In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the re…
CVE-2025-71389 CRITICAL Patched 10.0 2026-07-23 Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) req…
CVE-2026-12692 CRITICAL Patched 9.8 2026-07-17 Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0…
CVE-2026-12693 CRITICAL Patched 9.4 2026-07-17 Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. …
CVE-2026-12694 CRITICAL Patched 9.1 2026-07-17 Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterpri…
CVE-2026-12701 CRITICAL 9.0 2026-07-20 A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directo…
CVE-2026-13147 CRITICAL Patched 9.1 2026-07-20 The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue …
CVE-2026-13439 CRITICAL 9.8 2026-07-21 The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 Th…
CVE-2026-13446 CRITICAL Patched 9.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound c…
CVE-2026-14282 CRITICAL 9.8 2026-07-23 The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in…
CVE-2026-14956 CRITICAL 9.8 2026-07-17 The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds…
CVE-2026-15011 CRITICAL 9.8 2026-07-23 The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due …
CVE-2026-15015 CRITICAL 9.8 2026-07-23 The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugi…
CVE-2026-15091 CRITICAL 9.3 2026-07-17 IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation.
CVE-2026-15899 CRITICAL 9.6 2026-07-20 Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (…
CVE-2026-15900 CRITICAL 9.6 2026-07-20 Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromi…