Skip to main content

Severity archive

Critical severity CVEs

Critical

43,582 critical severity CVEs — 43,582 Critical, 125,411 High, 163,732 Medium, 17,996 Low, 2,142 Unrated across the current result set.

CVE-2026-63766

Published Jul 20, 2026

GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox va…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-44231

Published Jul 20, 2026

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-16337

Published Jul 20, 2026

Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated b…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-64193

Published Jul 20, 2026

Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
32.6

CVE-2026-62414

Published Jul 20, 2026

Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply access control to frontend page…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-61900

Published Jul 20, 2026

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file up…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-61425

Published Jul 20, 2026

Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin a…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-61424

Published Jul 20, 2026

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated f…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-60034

Published Jul 20, 2026

Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-60032

Published Jul 20, 2026

Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, le…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-39878

Published Jul 20, 2026

Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbi…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-54051

Published Jul 20, 2026

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`),…

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-41252

Published Jul 20, 2026

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. The…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-35048

Published Jul 20, 2026

The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper saniti…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-51027

Published Jul 20, 2026

An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-46428

Published Jul 20, 2026

lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's `boring-tls` integration silently disables TLS…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
22.6

CVE-2026-46412

Published Jul 20, 2026

@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker u…

CVSS 10.0 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2026-35198

Published Jul 20, 2026

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to i…

CVSS 9.0 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-63071

Published Jul 20, 2026

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class co…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-62183

Published Jul 20, 2026

Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is configured, b…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
25.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-57308

Published Jul 20, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve exec…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-53421

Published Jul 20, 2026

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-53405

Published Jul 20, 2026

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-12701

Published Jul 20, 2026

A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory trav…

CVSS 9.0 · Critical
evidence mentions
10
Buzz score
34.0

CVE-2026-57309

Published Jul 20, 2026

A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in HTTP header resulting in Blin…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0
Showing 551-575 of 43,582 CVEsPage 23 of 1744