Search
7,875 CVEs · Critical severity
CVEs (7,875, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 7,875 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50093 | CRITICAL | 9.0 | 2026-09-08 | A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Co… | |
| CVE-2026-66768 | CRITICAL | 9.0 | 2026-09-08 | SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit th… | |
| CVE-2026-84803 | CRITICAL | 9.0 | 2026-09-02 | SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. A… | |
| CVE-2026-84324 | CRITICAL | Patched | 9.0 | 2026-09-02 | Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromi… |
| CVE-2026-75604 | CRITICAL | Patched | 9.0 | 2026-09-01 | Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without C… |
| CVE-2026-73700 | CRITICAL | Patched | 9.0 | 2026-09-01 | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-s… |
| CVE-2026-73701 | CRITICAL | Patched | 9.0 | 2026-09-01 | An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain precond… |
| CVE-2026-79687 | CRITICAL | 9.0 | 2026-09-01 | Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this v… | |
| CVE-2026-84200 | CRITICAL | Patched | 9.0 | 2026-09-01 | Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive … |
| CVE-2026-40541 | CRITICAL | Patched | 9.0 | 2026-08-28 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows re… |
| CVE-2026-77551 | CRITICAL | 9.0 | 2026-08-26 | A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Connect Display Cast Pro to … | |
| CVE-2026-77549 | CRITICAL | 9.0 | 2026-08-26 | A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices … | |
| CVE-2026-77545 | CRITICAL | 9.0 | 2026-08-26 | A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running … | |
| CVE-2026-62674 | CRITICAL | Patched | 9.0 | 2026-08-21 | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permissio… |
| CVE-2026-32475 | CRITICAL | 9.0 | 2026-08-19 | Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1. | |
| CVE-2026-72530 | CRITICAL | Patched | 9.0 | 2026-08-19 | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a… |
| CVE-2026-18937 | CRITICAL | Patched | 9.0 | 2026-08-19 | The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthentic… |
| CVE-2026-70980 | CRITICAL | 9.0 | 2026-08-18 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported … | |
| CVE-2026-62988 | CRITICAL | Patched | 9.0 | 2026-08-18 | Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps.get, and Ftps.listing … |
| CVE-2026-61029 | CRITICAL | 9.0 | 2026-08-18 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1… | |
| CVE-2026-75130 | CRITICAL | 9.0 | 2026-08-18 | Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsaniti… | |
| CVE-2026-75625 | CRITICAL | 9.0 | 2026-08-18 | Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 … | |
| CVE-2026-14564 | CRITICAL | Patched | 9.0 | 2026-08-17 | Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data… |
| CVE-2026-74800 | CRITICAL | 9.0 | 2026-08-17 | SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. A… | |
| CVE-2026-73052 | CRITICAL | 9.0 | 2026-08-15 | SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers c… |