Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

6,131 CVEs · Critical severity

CVEs (6,131, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 6,131 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-16723 CRITICAL 9.0 2026-07-23 A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no Au…
CVE-2026-61223 CRITICAL 9.0 2026-07-21 Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). Supported versions that are affected are 8.…
CVE-2026-61204 CRITICAL 9.0 2026-07-21 Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). The supported version that is affected …
CVE-2026-61201 CRITICAL 9.0 2026-07-21 Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.2.23. …
CVE-2026-61174 CRITICAL 9.0 2026-07-21 Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. …
CVE-2026-60424 CRITICAL 9.0 2026-07-21 Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.…
CVE-2026-60249 CRITICAL 9.0 2026-07-21 Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 an…
CVE-2026-35198 CRITICAL 9.0 2026-07-20 HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team memb…
CVE-2026-12701 CRITICAL 9.0 2026-07-20 A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directo…
CVE-2026-64106 CRITICAL 9.0 2026-07-19 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits Userspace can restore an …
CVE-2026-11386 CRITICAL 9.0 2026-07-16 An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /et…
CVE-2026-62378 CRITICAL Patched 9.0 2026-07-15 RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/preview-modal.tsx and compo…
CVE-2026-48327 CRITICAL 9.0 2026-07-14 ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this is…
CVE-2026-57898 CRITICAL Patched 9.0 2026-07-14 In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary fil…
CVE-2026-54527 CRITICAL Patched 9.0 2026-07-08 JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when re…
CVE-2026-4375 CRITICAL 9.0 2026-07-07 The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, …
CVE-2026-58289 CRITICAL Patched 9.0 2026-07-03 Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-55116 CRITICAL Patched 9.0 2026-07-02 A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices runnin…
CVE-2026-57623 CRITICAL 9.0 2026-07-02 Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.
CVE-2025-23350 CRITICAL 9.0 2026-07-01 NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by craft&hellip;
CVE-2025-23351 CRITICAL 9.0 2026-07-01 NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by craft&hellip;
CVE-2026-10539 CRITICAL 9.0 2026-07-01 A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated att&hellip;
CVE-2026-54636 CRITICAL Patched 9.0 2026-06-26 Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron co&hellip;
CVE-2026-45405 CRITICAL Patched 9.0 2026-06-26 Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/zip archives into temporary directories without sanit&hellip;
CVE-2026-45406 CRITICAL Patched 9.0 2026-06-26 Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-includes/ git repository directory to the host and th&hellip;