Search
1,115 CVEs · Critical severity
CVEs (1,115, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 1,115 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16723 | CRITICAL | 9.0 | 2026-07-23 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no Au… | |
| CVE-2026-61223 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). Supported versions that are affected are 8.… | |
| CVE-2026-61204 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). The supported version that is affected … | |
| CVE-2026-61201 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.2.23. … | |
| CVE-2026-61174 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. … | |
| CVE-2026-60424 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.… | |
| CVE-2026-60249 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 an… | |
| CVE-2026-35198 | CRITICAL | 9.0 | 2026-07-20 | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team memb… | |
| CVE-2026-12701 | CRITICAL | 9.0 | 2026-07-20 | A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directo… | |
| CVE-2026-64106 | CRITICAL | 9.0 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits Userspace can restore an … | |
| CVE-2026-11386 | CRITICAL | 9.0 | 2026-07-16 | An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /et… | |
| CVE-2026-62378 | CRITICAL | Patched | 9.0 | 2026-07-15 | RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/preview-modal.tsx and compo… |
| CVE-2026-48327 | CRITICAL | 9.0 | 2026-07-14 | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this is… | |
| CVE-2026-57898 | CRITICAL | Patched | 9.0 | 2026-07-14 | In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary fil… |
| CVE-2026-54527 | CRITICAL | Patched | 9.0 | 2026-07-08 | JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when re… |
| CVE-2026-4375 | CRITICAL | 9.0 | 2026-07-07 | The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, … | |
| CVE-2026-58289 | CRITICAL | Patched | 9.0 | 2026-07-03 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-55116 | CRITICAL | Patched | 9.0 | 2026-07-02 | A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices runnin… |
| CVE-2026-57623 | CRITICAL | 9.0 | 2026-07-02 | Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions. | |
| CVE-2025-23350 | CRITICAL | 9.0 | 2026-07-01 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by craft… | |
| CVE-2025-23351 | CRITICAL | 9.0 | 2026-07-01 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by craft… | |
| CVE-2026-10539 | CRITICAL | 9.0 | 2026-07-01 | A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated att… | |
| CVE-2026-54636 | CRITICAL | Patched | 9.0 | 2026-06-26 | Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron co… |
| CVE-2026-45405 | CRITICAL | Patched | 9.0 | 2026-06-26 | Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/zip archives into temporary directories without sanit… |
| CVE-2026-45406 | CRITICAL | Patched | 9.0 | 2026-06-26 | Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-includes/ git repository directory to the host and th… |