Search
3,684 CVEs · Critical severity
CVEs (3,684, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 3,684 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9862 | CRITICAL | Patched | 9.8 | 2026-06-15 | Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to t… |
| CVE-2026-9810 | CRITICAL | Patched | 9.8 | 2026-07-17 | The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unaut… |
| CVE-2026-9733 | CRITICAL | 9.1 | 2026-06-23 | Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the constructor, th… | |
| CVE-2026-9726 | CRITICAL | Patched | 9.8 | 2026-07-10 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This iss… |
| CVE-2026-9725 | CRITICAL | 9.1 | 2026-07-03 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is du… | |
| CVE-2026-9711 | CRITICAL | 9.8 | 2026-06-30 | The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and… | |
| CVE-2026-9701 | CRITICAL | 9.8 | 2026-07-08 | The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of th… | |
| CVE-2026-9695 | CRITICAL | 9.8 | 2026-07-08 | An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to the server. | |
| CVE-2026-9691 | CRITICAL | 9.8 | 2026-06-15 | Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. | |
| CVE-2026-9648 | CRITICAL | 9.1 | 2026-06-11 | The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside… | |
| CVE-2026-9586 | CRITICAL | Patched | 9.8 | 2026-07-17 | An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> … |
| CVE-2026-9487 | CRITICAL | Patched | 9.1 | 2026-08-03 | XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolves the SignedInfo Refere… |
| CVE-2026-9390 | CRITICAL | Patched | 9.1 | 2026-08-03 | XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions by concatenating the Si… |
| CVE-2026-9273 | CRITICAL | 9.3 | 2026-08-05 | The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in a… | |
| CVE-2026-9265 | CRITICAL | Patched | 9.1 | 2026-06-20 | Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_attribute() copies a UTF8STRING ASN.1 attribute valu… |
| CVE-2026-9202 | CRITICAL | Patched | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented … |
| CVE-2026-9198 | CRITICAL | Patched | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code… |
| CVE-2026-9195 | CRITICAL | Patched | 9.3 | 2026-08-05 | A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administ… |
| CVE-2026-9193 | CRITICAL | Patched | 9.9 | 2026-08-05 | An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privi… |
| CVE-2026-9192 | CRITICAL | Patched | 9.8 | 2026-08-05 | An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass pass… |
| CVE-2026-9190 | CRITICAL | Patched | 9.1 | 2026-08-05 | An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and a… |
| CVE-2026-9182 | CRITICAL | Patched | 9.8 | 2026-07-06 | Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endp… |
| CVE-2026-9181 | CRITICAL | Patched | 9.8 | 2026-07-06 | Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by se… |
| CVE-2026-9158 | CRITICAL | Patched | 9.8 | 2026-06-18 | In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subseq… |
| CVE-2026-9142 | CRITICAL | Patched | 9.1 | 2026-06-19 | There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopback. This may allow an u… |