Skip to main content

Severity archive

Critical severity CVEs

Critical

43,854 critical severity CVEs — 43,854 Critical, 126,433 High, 163,847 Medium, 18,047 Low, 1,893 Unrated across the current result set.

CVE-2026-52470

Published Jul 21, 2026

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-52469

Published Jul 21, 2026

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml file

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-47708

Published Jul 21, 2026

MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` API and CLI is directly interpo…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-30631

Published Jul 21, 2026

An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrary code via crafted path to `computer_wr…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-64879

Published Jul 21, 2026

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve com…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-64878

Published Jul 21, 2026

Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via th…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-59147

Published Jul 21, 2026

Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find. The attach-time validator dsu_validate_h…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-59145

Published Jul 21, 2026

Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find. The attach-time validator si_valida…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-59144

Published Jul 21, 2026

Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time validator ring_validate_header…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-50755

Published Jul 21, 2026

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-64877

Published Jul 21, 2026

An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-59142

Published Jul 21, 2026

Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The attach-time validator shm_validate…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-59141

Published Jul 21, 2026

Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked. The attach-time validator rdx_validat…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-59140

Published Jul 21, 2026

Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. The attach-time validator ss_v…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-59139

Published Jul 21, 2026

Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked. The attach-time validator reqrep_…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2016-20096

Published Jul 21, 2026

Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipu…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
29.1

CVE-2026-47416

Published Jul 21, 2026

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspace…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-47413

Published Jul 21, 2026

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-47410

Published Jul 21, 2026

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret def…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-47407

Published Jul 21, 2026

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources under `/api/v1/workspaces/{works…

CVSS 9.4 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-64825

Published Jul 21, 2026

Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem…

CVSS 9.0 · Critical
evidence mentions
4
Buzz score
22.6

CVE-2026-64824

Published Jul 21, 2026

Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem pa…

CVSS 9.3 · Critical
evidence mentions
6
Buzz score
26.0

CVE-2026-47396

Published Jul 21, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent control API without authentication when `CALL_SERVER_TOKEN…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-47393

Published Jul 21, 2026

PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.generate_api_server_code`) tha…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-47392

Published Jul 21, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tools/pytho…

CVSS 9.9 · Critical
evidence mentions
3
Buzz score
18.9
Showing 626-650 of 43,854 CVEsPage 26 of 1755