Search
1,528 CVEs · Critical severity
CVEs (1,528, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 1,528 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61516 | CRITICAL | 9.8 | 2026-09-08 | Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password… | |
| CVE-2026-12744 | CRITICAL | Patched | 9.8 | 2026-09-08 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server. |
| CVE-2026-12745 | CRITICAL | Patched | 9.8 | 2026-09-08 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server. |
| CVE-2026-12645 | CRITICAL | Patched | 9.9 | 2026-09-08 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. |
| CVE-2026-12646 | CRITICAL | Patched | 9.9 | 2026-09-08 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. |
| CVE-2026-12647 | CRITICAL | Patched | 9.9 | 2026-09-08 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. |
| CVE-2026-12650 | CRITICAL | Patched | 9.9 | 2026-09-08 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. |
| CVE-2026-78234 | CRITICAL | 9.9 | 2026-09-08 | A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client cert… | |
| CVE-2026-71376 | CRITICAL | Patched | 9.8 | 2026-09-08 | OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 1… |
| CVE-2026-71377 | CRITICAL | Patched | 9.8 | 2026-09-08 | Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 be… |
| CVE-2026-62645 | CRITICAL | 9.8 | 2026-09-08 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and … | |
| CVE-2026-50093 | CRITICAL | 9.0 | 2026-09-08 | A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Co… | |
| CVE-2026-71374 | CRITICAL | Patched | 9.8 | 2026-09-08 | Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 1… |
| CVE-2026-86510 | CRITICAL | 9.9 | 2026-09-08 | A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to… | |
| CVE-2026-76969 | CRITICAL | 9.4 | 2026-09-08 | @sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated at… | |
| CVE-2026-86509 | CRITICAL | 9.6 | 2026-09-08 | A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulati… | |
| CVE-2026-66768 | CRITICAL | 9.0 | 2026-09-08 | SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit th… | |
| CVE-2026-58240 | CRITICAL | 9.8 | 2026-09-08 | SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with… | |
| CVE-2026-44756 | CRITICAL | 10.0 | 2026-09-08 | A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a craf… | |
| CVE-2026-86542 | CRITICAL | Patched | 9.1 | 2026-09-07 | knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can sup… |
| CVE-2026-86543 | CRITICAL | Patched | 9.8 | 2026-09-07 | knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attack… |
| CVE-2026-75650 | CRITICAL | 10.0 | 2026-09-07 | Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the co… | |
| CVE-2026-86480 | CRITICAL | Patched | 9.8 | 2026-09-07 | In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges |
| CVE-2026-86478 | CRITICAL | Patched | 9.8 | 2026-09-07 | In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address |
| CVE-2026-7861 | CRITICAL | 9.8 | 2026-09-07 | Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (… |