Search
478 CVEs · Critical severity
CVEs (478)
Showing 1–25 of 478
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16723 | CRITICAL | 9.0 | 2026-07-23 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no Au… | |
| CVE-2026-61223 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). Supported versions that are affected are 8.… | |
| CVE-2026-61204 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). The supported version that is affected … | |
| CVE-2026-61201 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.2.23. … | |
| CVE-2026-61174 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. … | |
| CVE-2026-60424 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.… | |
| CVE-2026-60249 | CRITICAL | 9.0 | 2026-07-21 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 an… | |
| CVE-2026-35198 | CRITICAL | 9.0 | 2026-07-20 | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team memb… | |
| CVE-2026-12701 | CRITICAL | 9.0 | 2026-07-20 | A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directo… | |
| CVE-2026-64106 | CRITICAL | 9.0 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits Userspace can restore an … | |
| CVE-2026-65701 | CRITICAL | 9.1 | 2026-07-23 | SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote att… | |
| CVE-2026-65907 | CRITICAL | Patched | 9.1 | 2026-07-23 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible |
| CVE-2026-65461 | CRITICAL | 9.1 | 2026-07-23 | Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions. | |
| CVE-2026-65455 | CRITICAL | 9.1 | 2026-07-23 | Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions. | |
| CVE-2026-27064 | CRITICAL | 9.1 | 2026-07-23 | Editor Arbitrary File Upload in Mailster <= 4.1.17 versions. | |
| CVE-2026-46738 | CRITICAL | 9.1 | 2026-07-22 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote ac… | |
| CVE-2026-40712 | CRITICAL | 9.1 | 2026-07-22 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote ac… | |
| CVE-2026-62144 | CRITICAL | 9.1 | 2026-07-22 | An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administ… | |
| CVE-2026-16232 | CRITICAL | Patched | 9.1 | 2026-07-22 | An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use … |
| CVE-2026-62546 | CRITICAL | 9.1 | 2026-07-21 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.8-12.2.15. … | |
| CVE-2026-61244 | CRITICAL | 9.1 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Argentina product of Oracle PeopleSoft (component: Manufacturing). The supported version that is affected is … | |
| CVE-2026-61235 | CRITICAL | 9.1 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland product of Oracle PeopleSoft (component: Global Payroll for Switzerland). The supported version … | |
| CVE-2026-61238 | CRITICAL | 9.1 | 2026-07-21 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is … | |
| CVE-2026-61197 | CRITICAL | 9.1 | 2026-07-21 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.… | |
| CVE-2026-61184 | CRITICAL | 9.1 | 2026-07-21 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version t… |