Search
3,673 CVEs · Critical severity
CVEs (3,673, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 3,673 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-45328 | CRITICAL | Patched | 9.3 | 2026-06-10 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_serv… |
| CVE-2025-66276 | CRITICAL | Patched | 9.8 | 2026-06-10 | QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later |
| CVE-2026-26240 | CRITICAL | Patched | 9.1 | 2026-06-10 | A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We… |
| CVE-2026-26241 | CRITICAL | Patched | 9.1 | 2026-06-10 | A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We… |
| CVE-2026-9067 | CRITICAL | Patched | 9.1 | 2026-06-10 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the … |
| CVE-2025-6254 | CRITICAL | 9.8 | 2026-06-10 | The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration()… | |
| CVE-2026-45550 | CRITICAL | 9.1 | 2026-06-10 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smon/routes.py:117-138) ga… | |
| CVE-2026-45552 | CRITICAL | 9.9 | 2026-06-10 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares only bp.before_request … | |
| CVE-2026-45556 | CRITICAL | 9.9 | 2026-06-10 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>/rule/<rule_id>/save ac… | |
| CVE-2026-45558 | CRITICAL | 9.9 | 2026-06-10 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoints (POST /api/service/… | |
| CVE-2026-53469 | CRITICAL | 9.1 | 2026-06-10 | A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper aut… | |
| CVE-2026-53470 | CRITICAL | 9.6 | 2026-06-10 | A flaw was found in migration-planner. An authenticated attacker could exploit an improper access control vulnerability in the `/api/v1/sources/{id}/image-url` endpoint. Th… | |
| CVE-2026-53471 | CRITICAL | 9.6 | 2026-06-10 | A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for authentication, but its UpdateSourceInventory and UpdateAgentStatus han… | |
| CVE-2026-53474 | CRITICAL | Patched | 9.6 | 2026-06-10 | A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a specially crafted RVTools .xlsx file. Due to improper… |
| CVE-2026-53475 | CRITICAL | Patched | 9.3 | 2026-06-10 | A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerabil… |
| CVE-2026-53476 | CRITICAL | Patched | 9.6 | 2026-06-10 | A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By craf… |
| CVE-2026-20253 | CRITICAL | Patched | 9.8 | 2026-06-10 | In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar … |
| CVE-2026-46614 | CRITICAL | Patched | 9.8 | 2026-06-10 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, the F… |
| CVE-2026-50545 | CRITICAL | Patched | 9.9 | 2026-06-10 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, the E… |
| CVE-2026-50563 | CRITICAL | Patched | 9.9 | 2026-06-10 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fissi… |
| CVE-2026-50564 | CRITICAL | Patched | 9.9 | 2026-06-10 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fissi… |
| CVE-2026-50566 | CRITICAL | Patched | 9.9 | 2026-06-10 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a ten… |
| CVE-2026-50638 | CRITICAL | Patched | 9.1 | 2026-06-10 | Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mut… |
| CVE-2026-0274 | CRITICAL | 9.1 | 2026-06-10 | An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access an… | |
| CVE-2026-46695 | CRITICAL | Patched | 10.0 | 2026-06-10 | Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version … |