Search
6,131 CVEs · Critical severity
CVEs (6,131, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 6,131 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-42933 | CRITICAL | 10.0 | 2026-07-23 | Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypa… | |
| CVE-2026-63732 | CRITICAL | Patched | 9.9 | 2026-07-23 | 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL… |
| CVE-2025-71389 | CRITICAL | Patched | 10.0 | 2026-07-23 | Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) req… |
| CVE-2024-58354 | CRITICAL | 9.9 | 2026-07-23 | cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_req… | |
| CVE-2026-47724 | CRITICAL | 9.9 | 2026-07-23 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trusts the bearer token alon… | |
| CVE-2026-15981 | CRITICAL | 9.8 | 2026-07-23 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_vali… | |
| CVE-2026-63359 | CRITICAL | 9.8 | 2026-07-23 | The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass … | |
| CVE-2026-6516 | CRITICAL | Patched | 10.0 | 2026-07-23 | Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API. |
| CVE-2026-65701 | CRITICAL | 9.1 | 2026-07-23 | SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote att… | |
| CVE-2026-65700 | CRITICAL | 9.8 | 2026-07-23 | h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbi… | |
| CVE-2026-47752 | CRITICAL | 9.9 | 2026-07-23 | Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notifica… | |
| CVE-2026-47668 | CRITICAL | 10.0 | 2026-07-23 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection … | |
| CVE-2026-65689 | CRITICAL | Patched | 9.8 | 2026-07-23 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated att… |
| CVE-2026-65688 | CRITICAL | Patched | 9.8 | 2026-07-23 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attac… |
| CVE-2026-65687 | CRITICAL | Patched | 9.8 | 2026-07-23 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attack… |
| CVE-2026-65907 | CRITICAL | Patched | 9.1 | 2026-07-23 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible |
| CVE-2026-65606 | CRITICAL | 9.6 | 2026-07-23 | SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an i… | |
| CVE-2026-65605 | CRITICAL | 9.6 | 2026-07-23 | SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/… | |
| CVE-2026-65471 | CRITICAL | 9.6 | 2026-07-23 | Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions. | |
| CVE-2026-65461 | CRITICAL | 9.1 | 2026-07-23 | Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions. | |
| CVE-2026-65455 | CRITICAL | 9.1 | 2026-07-23 | Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions. | |
| CVE-2026-64813 | CRITICAL | Patched | 10.0 | 2026-07-23 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session |
| CVE-2026-64812 | CRITICAL | Patched | 10.0 | 2026-07-23 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session |
| CVE-2026-61951 | CRITICAL | 9.8 | 2026-07-23 | Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions. | |
| CVE-2026-61950 | CRITICAL | 9.3 | 2026-07-23 | Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. |