Skip to main content

Severity archive

Critical severity CVEs

Critical

43,400 critical severity CVEs — 43,400 Critical, 124,858 High, 163,347 Medium, 17,956 Low, 2,043 Unrated across the current result set.

CVE-2026-63030

Published Jul 17, 2026

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (…

CVSS 9.8 · Critical
evidence mentions
21
Buzz score
93.0
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-52199

Published Jul 17, 2026

An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-42168

Published Jul 17, 2026

django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. These fields are passed directly to os.system() in p…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-36669

Published Jul 17, 2026

An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-15091

Published Jul 17, 2026

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation.

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-51677

Published Jul 17, 2026

An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can lead to unexpected behavior.

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2026-9202

Published Jul 17, 2026

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deploym…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-9198

Published Jul 17, 2026

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (execu…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-9586

Published Jul 17, 2026

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and dir…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-8297

Published Jul 17, 2026

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services I…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-54496

Published Jul 17, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar mu…

CVSS 9.3 · Critical
evidence mentions
7
Buzz score
30.8

CVE-2026-12694

Published Jul 17, 2026

Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Vide…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-12693

Published Jul 17, 2026

Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This is…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-12692

Published Jul 17, 2026

Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 befo…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-60024

Published Jul 17, 2026

The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-51080

Published Jul 17, 2026

libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2024-23564

Published Jul 17, 2026

HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-9810

Published Jul 17, 2026

The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthentica…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-15982

Published Jul 17, 2026

The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-62241

Published Jul 17, 2026

clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Be…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-62232

Published Jul 17, 2026

Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authorization, d…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-14956

Published Jul 17, 2026

The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds parame…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-44182

Published Jul 16, 2026

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions prior to 3.3.0, the se…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0
Showing 476-500 of 43,400 CVEsPage 20 of 1736