Skip to main content

Severity archive

Critical severity CVEs

Critical

43,370 critical severity CVEs — 43,370 Critical, 124,776 High, 163,222 Medium, 17,939 Low, 2,047 Unrated across the current result set.

CVE-2026-63800

Published Jul 19, 2026

In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() When hitting the NFS_LAYOUT_RETURN branch in pnfs_update_lay…

CVSS 9.8 · Critical
evidence mentions
9
Buzz score
33.0

CVE-2026-63795

Published Jul 19, 2026

In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error path When p9_client_walk() is called with clone set to fal…

CVSS 10.0 · Critical
evidence mentions
7
Buzz score
30.8

CVE-2026-53399

Published Jul 19, 2026

In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure nfs4_alloc_stid() publishes the new stid into cl->cl_stateids v…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
27.9

CVE-2026-53398

Published Jul 19, 2026

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfsd4_decode_secinfo_no_name() currently initializes sin_exp a…

CVSS 9.8 · Critical
evidence mentions
9
Buzz score
33.0

CVE-2026-53384

Published Jul 19, 2026

In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails dw8250_probe() registers the 8250 port…

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
32.0

CVE-2026-9323

Published Jul 18, 2026

The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that use Pyt…

CVSS 9.2 · Critical
evidence mentions
6
Buzz score
26.0

CVE-2026-16117

Published Jul 18, 2026

Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for r…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2025-71392

Published Jul 18, 2026

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command. An authenticated System User…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2024-58366

Published Jul 18, 2026

SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can sup…

CVSS 9.0 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-47865

Published Jul 18, 2026

VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authent…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2026-55518

Published Jul 17, 2026

Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in the UI and G…

CVSS 9.6 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-54466

Published Jul 17, 2026

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that all…

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-54159

Published Jul 17, 2026

PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected search filters from the request…

CVSS 10.0 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-52348

Published Jul 17, 2026

cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-48062

Published Jul 17, 2026

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived guessed ex…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-63030

Published Jul 17, 2026

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (…

CVSS 9.8 · Critical
evidence mentions
21
Buzz score
93.0
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-52199

Published Jul 17, 2026

An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-42168

Published Jul 17, 2026

django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. These fields are passed directly to os.system() in p…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-36669

Published Jul 17, 2026

An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Showing 426-450 of 43,370 CVEsPage 18 of 1735