Search
1,528 CVEs · Critical severity
CVEs (1,528, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 1,528 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44756 | CRITICAL | 10.0 | 2026-09-08 | A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a craf… | |
| CVE-2026-75650 | CRITICAL | 10.0 | 2026-09-07 | Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the co… | |
| CVE-2026-86296 | CRITICAL | 10.0 | 2026-09-07 | A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This ma… | |
| CVE-2026-86152 | CRITICAL | 10.0 | 2026-09-06 | A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. … | |
| CVE-2026-70352 | CRITICAL | 10.0 | 2026-09-03 | Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-83711 | CRITICAL | 10.0 | 2026-09-03 | Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-85061 | CRITICAL | Patched | 10.0 | 2026-09-03 | MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap… |
| CVE-2026-4357 | CRITICAL | 10.0 | 2026-09-02 | The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for un… | |
| CVE-2026-83548 | CRITICAL | Patched | 10.0 | 2026-09-01 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker c… |
| CVE-2026-76658 | CRITICAL | Patched | 10.0 | 2026-09-01 | A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to… |
| CVE-2026-76657 | CRITICAL | Patched | 10.0 | 2026-09-01 | Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing aut… |
| CVE-2026-82971 | CRITICAL | 10.0 | 2026-08-31 | A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This mani… | |
| CVE-2026-81780 | CRITICAL | 10.0 | 2026-08-31 | Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. | |
| CVE-2026-81779 | CRITICAL | 10.0 | 2026-08-31 | Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0… | |
| CVE-2026-82970 | CRITICAL | 10.0 | 2026-08-31 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue… | |
| CVE-2026-82693 | CRITICAL | 10.0 | 2026-08-31 | A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executin… | |
| CVE-2026-82694 | CRITICAL | 10.0 | 2026-08-31 | A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manip… | |
| CVE-2026-82695 | CRITICAL | 10.0 | 2026-08-31 | A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation … | |
| CVE-2026-82542 | CRITICAL | 10.0 | 2026-08-30 | A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component B… | |
| CVE-2026-82456 | CRITICAL | 10.0 | 2026-08-29 | argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Atta… | |
| CVE-2026-54745 | CRITICAL | Patched | 10.0 | 2026-08-28 | Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthentica… |
| CVE-2026-82222 | CRITICAL | 10.0 | 2026-08-28 | Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1. | |
| CVE-2026-81735 | CRITICAL | 10.0 | 2026-08-27 | startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound th… | |
| CVE-2026-81096 | CRITICAL | 10.0 | 2026-08-27 | ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor to… | |
| CVE-2026-77554 | CRITICAL | 10.0 | 2026-08-26 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the … |