Search
196 CVEs · Critical severity
CVEs (196)
Showing 1–25 of 196
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50093 | CRITICAL | 9.0 | 2026-09-08 | A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Co… | |
| CVE-2026-66768 | CRITICAL | 9.0 | 2026-09-08 | SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit th… | |
| CVE-2026-84803 | CRITICAL | 9.0 | 2026-09-02 | SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. A… | |
| CVE-2026-84324 | CRITICAL | Patched | 9.0 | 2026-09-02 | Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromi… |
| CVE-2026-75604 | CRITICAL | Patched | 9.0 | 2026-09-01 | Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without C… |
| CVE-2026-73700 | CRITICAL | Patched | 9.0 | 2026-09-01 | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-s… |
| CVE-2026-73701 | CRITICAL | Patched | 9.0 | 2026-09-01 | An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain precond… |
| CVE-2026-79687 | CRITICAL | 9.0 | 2026-09-01 | Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this v… | |
| CVE-2026-84200 | CRITICAL | Patched | 9.0 | 2026-09-01 | Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive … |
| CVE-2026-86542 | CRITICAL | Patched | 9.1 | 2026-09-07 | knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can sup… |
| CVE-2026-86153 | CRITICAL | 9.1 | 2026-09-06 | A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation lead… | |
| CVE-2026-86151 | CRITICAL | 9.1 | 2026-09-06 | A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Mana… | |
| CVE-2026-86148 | CRITICAL | 9.1 | 2026-09-05 | A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipu… | |
| CVE-2026-86149 | CRITICAL | 9.1 | 2026-09-05 | A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument inte… | |
| CVE-2026-86190 | CRITICAL | 9.1 | 2026-09-05 | WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and li… | |
| CVE-2026-52766 | CRITICAL | Patched | 9.1 | 2026-09-05 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array fro… |
| CVE-2026-81939 | CRITICAL | 9.1 | 2026-09-04 | A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outsid… | |
| CVE-2026-78327 | CRITICAL | 9.1 | 2026-09-04 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Manageme… | |
| CVE-2026-78328 | CRITICAL | 9.1 | 2026-09-04 | A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileg… | |
| CVE-2026-75431 | CRITICAL | 9.1 | 2026-09-04 | PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code. | |
| CVE-2026-75160 | CRITICAL | 9.1 | 2026-09-04 | An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi. | |
| CVE-2026-85684 | CRITICAL | 9.1 | 2026-09-04 | marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attac… | |
| CVE-2026-85667 | CRITICAL | 9.1 | 2026-09-04 | xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into t… | |
| CVE-2026-85184 | CRITICAL | Patched | 9.1 | 2026-09-04 | @fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolve… |
| CVE-2026-85430 | CRITICAL | 9.1 | 2026-09-03 | MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attack… |