Skip to main content

Severity archive

Critical severity CVEs

Critical

43,402 critical severity CVEs — 43,402 Critical, 124,867 High, 163,363 Medium, 17,956 Low, 2,045 Unrated across the current result set.

CVE-2026-14956

Published Jul 17, 2026

The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds parame…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-44182

Published Jul 16, 2026

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions prior to 3.3.0, the se…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-44181

Published Jul 16, 2026

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions 2.0.0rc2 and above, pr…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-57075

Published Jul 16, 2026

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec. The base64 decoder in the bundled libsyck indexes the…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2026-53412

Published Jul 16, 2026

Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account…

CVSS 9.8 · Critical
evidence mentions
13
Buzz score
42.4

CVE-2026-44180

Published Jul 16, 2026

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Versions 2.0.0rc1 and above prior…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-38158

Published Jul 16, 2026

A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL statemen…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-63089

Published Jul 16, 2026

WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attacker…

CVSS 9.0 · Critical
evidence mentions
3
Buzz score
20.4

CVE-2026-15422

Published Jul 16, 2026

The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chunk. Since this lookup runs dur…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2026-46515

Published Jul 16, 2026

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pinsets, fm_show_context, fm_get_…

CVSS 9.3 · Critical
evidence mentions
6
Buzz score
24.5

CVE-2026-46512

Published Jul 16, 2026

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, dest, url, extension, code, and…

CVSS 9.9 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-45336

Published Jul 16, 2026

HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-coded F…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-63087

Published Jul 16, 2026

Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the int…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-57074

Published Jul 16, 2026

XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or elem…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2026-57073

Published Jul 16, 2026

HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or ele…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
27.6

CVE-2026-46621

Published Jul 16, 2026

Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text u…

CVSS 9.1 · Critical
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-46562

Published Jul 16, 2026

Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algo…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-45568

Published Jul 16, 2026

zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path…

CVSS 9.9 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-44632

Published Jul 16, 2026

Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlg…

CVSS 9.1 · Critical
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-3031

Published Jul 16, 2026

Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg 0.9.0 that was last updated in 2004. Epeg is a fast JPEG…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2026-59866

Published Jul 16, 2026

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sani…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-59865

Published Jul 16, 2026

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency n…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-59864

Published Jul 16, 2026

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_temp…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-54733

Published Jul 16, 2026

The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft O…

CVSS 9.3 · Critical
evidence mentions
7
Buzz score
25.8

CVE-2026-45695

Published Jul 16, 2026

Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
21.1
Showing 501-525 of 43,402 CVEsPage 21 of 1737