Search
1,115 CVEs · Critical severity
CVEs (1,115, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 1,115 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-12485 | CRITICAL | 10.0 | 2026-06-24 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the… | |
| CVE-2026-12486 | CRITICAL | 9.1 | 2026-06-24 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to com… | |
| CVE-2026-12846 | CRITICAL | 10.0 | 2026-06-24 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the… | |
| CVE-2026-12847 | CRITICAL | 10.0 | 2026-06-24 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the… | |
| CVE-2026-12848 | CRITICAL | 10.0 | 2026-06-24 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the… | |
| CVE-2026-12849 | CRITICAL | 9.1 | 2026-06-24 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to com… | |
| CVE-2026-12850 | CRITICAL | 9.1 | 2026-06-24 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to com… | |
| CVE-2026-12851 | CRITICAL | 9.1 | 2026-06-24 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to com… | |
| CVE-2026-12416 | CRITICAL | 9.8 | 2026-06-24 | The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invo… | |
| CVE-2026-12417 | CRITICAL | 9.8 | 2026-06-24 | The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and includ… | |
| CVE-2026-52914 | CRITICAL | Patched | 9.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix fragment reassembly length accounting batman-adv keeps a running payload length for qu… |
| CVE-2026-52924 | CRITICAL | Patched | 9.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only invoked when the assoc… |
| CVE-2026-52931 | CRITICAL | Patched | 9.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid use of uninit sender vars batadv_tp_recv_ack() and batadv_tp_stop() are on… |
| CVE-2026-56237 | CRITICAL | Patched | 9.1 | 2026-06-24 | Capgo before 12.128.2 contains a broken authentication vulnerability in its API key generation mechanism. API keys are exposed in frontend requests, and the backend fails t… |
| CVE-2026-56111 | CRITICAL | Patched | 9.1 | 2026-06-24 | Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-bounds write vulnerability in the M421 G-code handle… |
| CVE-2026-56121 | CRITICAL | Patched | 9.8 | 2026-06-24 | Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a cra… |
| CVE-2026-52955 | CRITICAL | Patched | 9.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crush_decode() A message of type CEPH_MSG_OSD_MAP conta… |
| CVE-2026-52958 | CRITICAL | Patched | 9.1 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in osdmap_decode() When decoding osd_state and osd_weight … |
| CVE-2026-52982 | CRITICAL | Patched | 9.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() syzbot reported a KASAN slab-use-after-f… |
| CVE-2026-52986 | CRITICAL | Patched | 9.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: don't use simple_strtoul Replace unsafe port parsing in epaddr_len(), ct_… |
| CVE-2026-52989 | CRITICAL | Patched | 9.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers Currently, when nvmet_tcp_build… |
| CVE-2026-52993 | CRITICAL | Patched | 9.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially reallocate the skb it i… |
| CVE-2026-52999 | CRITICAL | Patched | 9.1 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix out-of-bounds read on option matching In nf_osf_match(), the nf_osf_hdr_… |
| CVE-2026-53002 | CRITICAL | Patched | 9.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Replace it with scnprintf, the buffer sizes are expected to… |
| CVE-2026-53006 | CRITICAL | Patched | 9.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching saddr and daddr before pskb_pull() is problematic since… |