Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

1,115 CVEs · Critical severity

CVEs (1,115, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 1,115 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9810 CRITICAL Patched 9.8 2026-07-17 The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unaut…
CVE-2026-9726 CRITICAL 9.8 2026-07-10 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This iss…
CVE-2026-9725 CRITICAL 9.1 2026-07-03 The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is du…
CVE-2026-9711 CRITICAL 9.8 2026-06-30 The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and…
CVE-2026-9701 CRITICAL 9.8 2026-07-08 The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of th…
CVE-2026-9695 CRITICAL 9.8 2026-07-08 An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to the server.
CVE-2026-9202 CRITICAL 9.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented …
CVE-2026-9198 CRITICAL 9.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code…
CVE-2026-9182 CRITICAL Patched 9.8 2026-07-06 Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endp…
CVE-2026-9181 CRITICAL Patched 9.8 2026-07-06 Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by se…
CVE-2026-9135 CRITICAL Patched 9.9 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies…
CVE-2026-9103 CRITICAL Patched 9.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The…
CVE-2026-9079 CRITICAL Patched 9.8 2026-07-03 libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent tra…
CVE-2026-9074 CRITICAL Patched 9.1 2026-07-08 IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
CVE-2026-8927 CRITICAL Patched 9.1 2026-07-03 When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between req…
CVE-2026-8926 CRITICAL Patched 9.1 2026-07-03 When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, cur…
CVE-2026-8925 CRITICAL Patched 9.8 2026-07-03 The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same p…
CVE-2026-8924 CRITICAL Patched 9.1 2026-07-03 A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled or…
CVE-2026-8859 CRITICAL Patched 9.9 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest c…
CVE-2026-8655 CRITICAL Patched 9.8 2026-06-30 Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is con…
CVE-2026-8635 CRITICAL Patched 9.9 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system command…
CVE-2026-8505 CRITICAL Patched 9.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The …
CVE-2026-8481 CRITICAL Patched 9.9 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint ac…
CVE-2026-8476 CRITICAL Patched 9.9 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's uns…
CVE-2026-8452 CRITICAL Patched 9.8 2026-06-30 Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a G…