Skip to main content

Severity archive

Critical severity CVEs

Critical

43,625 critical severity CVEs — 43,625 Critical, 125,511 High, 163,810 Medium, 18,002 Low, 2,153 Unrated across the current result set.

CVE-2026-64606

Published Jul 21, 2026

Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-64609

Published Jul 21, 2026

Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-64608

Published Jul 21, 2026

Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-62415

Published Jul 21, 2026

Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthen…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-13439

Published Jul 21, 2026

The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is d…

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
28.5

CVE-2026-15901

Published Jul 20, 2026

Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security sev…

CVSS 9.6 · Critical
evidence mentions
4
Buzz score
36.1
Vendor/product tagsBeta · best-effort

CVE-2026-15900

Published Jul 20, 2026

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium secu…

CVSS 9.6 · Critical
evidence mentions
4
Buzz score
36.1
Vendor/product tagsBeta · best-effort

CVE-2026-15899

Published Jul 20, 2026

Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromiu…

CVSS 9.6 · Critical
evidence mentions
4
Buzz score
36.1
Vendor/product tagsBeta · best-effort

CVE-2026-64625

Published Jul 20, 2026

AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and back…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-52656

Published Jul 20, 2026

An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary code via a crafted FEX file

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2024-51315

Published Jul 20, 2026

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2024-51314

Published Jul 20, 2026

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2024-51312

Published Jul 20, 2026

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-53595

Published Jul 20, 2026

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenC…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-13380

Published Jul 20, 2026

VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these resp…

CVSS 9.0 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2024-51313

Published Jul 20, 2026

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2024-51311

Published Jul 20, 2026

The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-63767

Published Jul 20, 2026

ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands b…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
22.6

CVE-2026-63766

Published Jul 20, 2026

GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox va…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-44231

Published Jul 20, 2026

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-16337

Published Jul 20, 2026

Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated b…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-64193

Published Jul 20, 2026

Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
32.6

CVE-2026-62414

Published Jul 20, 2026

Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply access control to frontend page…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-61900

Published Jul 20, 2026

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file up…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-61425

Published Jul 20, 2026

Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin a…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
21.0
Showing 576-600 of 43,625 CVEsPage 24 of 1745