Skip to main content

Severity archive

Critical severity CVEs

Critical

43,458 critical severity CVEs — 43,458 Critical, 125,144 High, 163,487 Medium, 17,970 Low, 2,179 Unrated across the current result set.

CVE-2026-52348

Published Jul 17, 2026

cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-48062

Published Jul 17, 2026

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived guessed ex…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-63030

Published Jul 17, 2026

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (…

CVSS 9.8 · Critical
evidence mentions
27
Buzz score
93.0
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-52199

Published Jul 17, 2026

An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-42168

Published Jul 17, 2026

django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. These fields are passed directly to os.system() in p…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-36669

Published Jul 17, 2026

An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-15091

Published Jul 17, 2026

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation.

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-51677

Published Jul 17, 2026

An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can lead to unexpected behavior.

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2026-9202

Published Jul 17, 2026

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deploym…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9198

Published Jul 17, 2026

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (execu…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9586

Published Jul 17, 2026

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and dir…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-8297

Published Jul 17, 2026

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services I…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-54496

Published Jul 17, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar mu…

CVSS 9.3 · Critical
evidence mentions
7
Buzz score
30.8

CVE-2026-12694

Published Jul 17, 2026

Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Vide…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-12693

Published Jul 17, 2026

Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This is…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-12692

Published Jul 17, 2026

Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 befo…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-60024

Published Jul 17, 2026

Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthen…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Showing 526-550 of 43,458 CVEsPage 22 of 1739