Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

208 CVEs · Critical severity

CVEs (208)

Showing 1–25 of 208

CVE ID Severity Patch CVSS Published Description
CVE-2023-54391 CRITICAL Patched 9.8 2026-09-01 Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers…
CVE-2024-11080 CRITICAL 9.8 2026-09-05 The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in t…
CVE-2025-67066 CRITICAL 9.8 2026-09-04 SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path
CVE-2025-9314 CRITICAL 9.8 2026-09-02 The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component
CVE-2026-10196 CRITICAL Patched 9.8 2026-09-05 The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc…
CVE-2026-11613 CRITICAL 9.8 2026-09-04 The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter paramet…
CVE-2026-12645 CRITICAL Patched 9.9 2026-09-08 A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
CVE-2026-12646 CRITICAL Patched 9.9 2026-09-08 A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
CVE-2026-12647 CRITICAL Patched 9.9 2026-09-08 A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
CVE-2026-12650 CRITICAL Patched 9.9 2026-09-08 A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
CVE-2026-12744 CRITICAL Patched 9.8 2026-09-08 A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
CVE-2026-12745 CRITICAL Patched 9.8 2026-09-08 A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
CVE-2026-13447 CRITICAL 9.8 2026-09-05 The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic sig…
CVE-2026-15354 CRITICAL 9.8 2026-09-04 The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `sub…
CVE-2026-16310 CRITICAL 9.8 2026-09-06 The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing vali…
CVE-2026-18210 CRITICAL Patched 9.8 2026-09-01 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and T…
CVE-2026-18550 CRITICAL 9.8 2026-09-01 The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to i…
CVE-2026-18658 CRITICAL 9.8 2026-09-04 IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execut…
CVE-2026-18765 CRITICAL 9.8 2026-09-01 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This …
CVE-2026-18808 CRITICAL 9.8 2026-09-01 Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This i…
CVE-2026-18922 CRITICAL 9.8 2026-09-07 A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can…
CVE-2026-18931 CRITICAL 9.1 2026-09-01 Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Retrieve Embedded Sensitive Data. Th…
CVE-2026-19117 CRITICAL 9.8 2026-09-02 Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects …
CVE-2026-19274 CRITICAL 9.6 2026-09-04 IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently dest…
CVE-2026-19593 CRITICAL 9.8 2026-09-01 OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a reposito…