Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,454 CVEs · Critical severity

CVEs (2,454, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 2,454 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-6951 CRITICAL Patched 9.8 2026-04-25 Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/S…
CVE-2026-31682 CRITICAL Patched 9.1 2026-04-25 In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: linearize skb before parsing ND options br_nd_send() parses neighbour discovery op…
CVE-2026-31685 CRITICAL Patched 9.4 2026-04-25 In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_eui64: reject invalid MAC header for all packets `eui64_mt6()` derives a modified EUI-…
CVE-2026-7037 CRITICAL 9.8 2026-04-26 A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component…
CVE-2026-42363 CRITICAL 9.3 2026-04-27 An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead …
CVE-2026-40453 CRITICAL Patched 9.9 2026-04-27 The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alon…
CVE-2026-40860 CRITICAL Patched 9.8 2026-04-27 JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms…
CVE-2026-41635 CRITICAL Patched 9.8 2026-04-27 Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the clas…
CVE-2026-33454 CRITICAL Patched 9.4 2026-04-27 The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters th…
CVE-2026-41409 CRITICAL Patched 9.8 2026-04-27 The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late af…
CVE-2026-22336 CRITICAL Patched 9.3 2026-04-27 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Directorist Booking allows SQL Injection.This issue affects Directoris…
CVE-2026-22337 CRITICAL Patched 9.8 2026-04-27 Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This issue affects Directorist Social Login: from n/a before 2.1.4.
CVE-2026-33453 CRITICAL Patched 10.0 2026-04-27 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's camel-coap component is v…
CVE-2026-7121 CRITICAL 9.8 2026-04-27 A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This ma…
CVE-2026-7122 CRITICAL 9.8 2026-04-27 A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. …
CVE-2026-7123 CRITICAL 9.8 2026-04-27 A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Perfor…
CVE-2026-7124 CRITICAL 9.8 2026-04-27 A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Affected by this vulnerability is the function setIpv6LanCfg of the file /cgi-bin/cstecgi.cgi of the…
CVE-2026-7125 CRITICAL 9.8 2026-04-27 A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi of the compon…
CVE-2026-30352 CRITICAL 9.8 2026-04-27 A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allows attackers to execute arbitrary code via providing …
CVE-2026-41462 CRITICAL 9.8 2026-04-27 ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is directly concatenated in…
CVE-2026-7136 CRITICAL 9.8 2026-04-27 A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setDmzCfg of the file /cgi-bin/cstecgi.cgi of the component C…
CVE-2026-7137 CRITICAL 9.8 2026-04-27 A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setStorageCfg of the file /cgi-bin/cstecgi.cgi of the componen…
CVE-2026-7138 CRITICAL 9.8 2026-04-27 A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setNtpCfg of the file /cgi-bin/cstecgi.cgi of the component CG…
CVE-2026-7139 CRITICAL 9.8 2026-04-27 A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler…
CVE-2026-7140 CRITICAL 9.8 2026-04-27 A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function CsteSystem of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. S…