CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-19660 CRITICAL

Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter

CVSS 9.8 EPSS n/a Oct 2, 2026
CVE-2026-14378 CRITICAL

DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow

CVSS 9.8 EPSS n/a Oct 2, 2026
CVE-2026-104480 CRITICAL

Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership

CVSS 9.4 EPSS n/a Oct 2, 2026
CVE-2026-86345 CRITICAL

389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result

CVSS 9.0 EPSS n/a Oct 1, 2026
CVE-2026-103764 CRITICAL

Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport

CVSS 9.3 EPSS n/a Oct 1, 2026
CVE-2026-18397 CRITICAL

SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability

CVSS 9.4 EPSS n/a Oct 1, 2026
CVE-2026-71449 CRITICAL

: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32:…

CVSS 9.3 EPSS n/a Oct 1, 2026
CVE-2026-55395 CRITICAL

Hardcoded Passwords in Teledyne FLIR Robots running Aware2

CVSS 9.4 EPSS n/a Oct 1, 2026
CVE-2026-55393 CRITICAL

Local File Inclusion in Teledyne FLIR Robots running Aware2

CVSS 10.0 EPSS n/a Oct 1, 2026
CVE-2026-14984 CRITICAL

Cleartext HTTP for Control Traffic in Teledyne FLIR Robots running Aware2

CVSS 9.4 EPSS n/a Oct 1, 2026
CVE-2026-102628 CRITICAL

Cadmos LTI exposure of sensitive information via debug mode

CVSS 9.2 EPSS n/a Oct 1, 2026
CVE-2026-102667 CRITICAL

Joyland AI WebView command injection

CVSS 9.0 EPSS n/a Oct 1, 2026
CVE-2026-56662 CRITICAL

GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side update request

CVSS 9.6 EPSS n/a Oct 1, 2026
CVE-2026-56660 CRITICAL

GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction

CVSS 9.1 EPSS n/a Oct 1, 2026
CVE-2026-53953 CRITICAL

GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover

CVSS 9.1 EPSS 0.06% Oct 1, 2026
CVE-2026-104286 KEV CRITICAL

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 thro…

CVSS 9.8 EPSS n/a Oct 1, 2026
CVE-2026-55083 CRITICAL

DHIS2: Unsafe Java Deserialization - Remote Code Execution (RCE)

CVSS 9.1 EPSS n/a Oct 1, 2026
CVE-2026-103922 CRITICAL

Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path

CVSS 9.3 EPSS n/a Oct 1, 2026
CVE-2026-96658 CRITICAL

Foreman: safemode bypass leading to rce

CVSS 9.9 EPSS n/a Oct 1, 2026
CVE-2026-96659 CRITICAL

Foreman: excessive permissions for viewer role on preview

CVSS 9.1 EPSS n/a Oct 1, 2026
CVE-2026-59797 CRITICAL

Apache HTTP Server: mod_ssl SSLRequire allows .htaccess ap_expr file-function

CVSS 9.8 EPSS n/a Oct 1, 2026
CVE-2026-13043 CRITICAL

WatchGuard Endpoint Security Missing Authentication in Kernel Memory Access Driver Allows Arbitrary Kernel Memory Access

CVSS 9.3 EPSS n/a Oct 1, 2026
CVE-2026-57941 CRITICAL

Apache HTTP Server: mod_http2 use-after-free / wild write via shared session->bbtmp re-entrancy

CVSS 9.8 EPSS n/a Oct 1, 2026
CVE-2026-56154 CRITICAL

Apache HTTP Server: mod_rewrite use-after-free via %{LA-U:HTTP:...}

CVSS 9.8 EPSS n/a Oct 1, 2026
CVE-2026-94620 CRITICAL

Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download)

CVSS 9.4 EPSS n/a Oct 1, 2026

Showing 1 to 25 CVEs · page 1 (more available)