Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

1,517 CVEs · Critical severity

CVEs (1,517, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 1,517 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-50093 CRITICAL 9.0 2026-09-08 A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Co&hellip;
CVE-2026-66768 CRITICAL 9.0 2026-09-08 SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit th&hellip;
CVE-2026-84803 CRITICAL 9.0 2026-09-02 SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. A&hellip;
CVE-2026-84324 CRITICAL Patched 9.0 2026-09-02 Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromi&hellip;
CVE-2026-75604 CRITICAL Patched 9.0 2026-09-01 Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without C&hellip;
CVE-2026-73700 CRITICAL Patched 9.0 2026-09-01 A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-s&hellip;
CVE-2026-73701 CRITICAL Patched 9.0 2026-09-01 An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain precond&hellip;
CVE-2026-79687 CRITICAL 9.0 2026-09-01 Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this v&hellip;
CVE-2026-84200 CRITICAL Patched 9.0 2026-09-01 Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive &hellip;
CVE-2026-40541 CRITICAL Patched 9.0 2026-08-28 An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows re&hellip;
CVE-2026-77551 CRITICAL 9.0 2026-08-26 A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Connect Display Cast Pro to &hellip;
CVE-2026-77549 CRITICAL 9.0 2026-08-26 A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices &hellip;
CVE-2026-77545 CRITICAL 9.0 2026-08-26 A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running &hellip;
CVE-2026-62674 CRITICAL Patched 9.0 2026-08-21 Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permissio&hellip;
CVE-2026-32475 CRITICAL 9.0 2026-08-19 Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.
CVE-2026-72530 CRITICAL Patched 9.0 2026-08-19 A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a&hellip;
CVE-2026-18937 CRITICAL Patched 9.0 2026-08-19 The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthentic&hellip;
CVE-2026-70980 CRITICAL 9.0 2026-08-18 Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported &hellip;
CVE-2026-62988 CRITICAL Patched 9.0 2026-08-18 Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps.get, and Ftps.listing &hellip;
CVE-2026-61029 CRITICAL 9.0 2026-08-18 Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1&hellip;
CVE-2026-75130 CRITICAL 9.0 2026-08-18 Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsaniti&hellip;
CVE-2026-75625 CRITICAL 9.0 2026-08-18 Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 &hellip;
CVE-2026-14564 CRITICAL Patched 9.0 2026-08-17 Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data&hellip;
CVE-2026-74800 CRITICAL 9.0 2026-08-17 SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. A&hellip;
CVE-2026-73052 CRITICAL 9.0 2026-08-15 SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers c&hellip;