Recent Critical Vulnerabilities

The latest critical severity CVEs, sorted by publication date. 50 critical vulnerabilities tracked.

50
Critical CVEs
Aug 11
Latest Published
15
CVSS 10.0
CVE-2026-46670 Aug 11, 2026

YesWiki SQL injection leaks all credentials (CVE-2026-46670)

CVSS 9.8
CVE-2026-72898 Aug 10, 2026

Metabase SQL injection grants admin access (CVE-2026-72898)

CVSS 10
CVE-2026-16812 Jul 27, 2026

VCO orchestator unauth access exploited (CVE-2026-16812)

CVSS 10
CVE-2026-55579 Jul 27, 2026

Pheditor hardcoded admin RCE (CVE-2026-55579) [PoC]

CVSS 9.8
CVE-2026-63077 Jul 27, 2026

TeamCity RCE exploited in the wild (CVE-2026-63077) [PoC]

CVSS 9.8 Jetbrains Teamcity
CVE-2026-47668 Jul 23, 2026

DbGate unauthenticated RCE (CVE-2026-47668) [PoC]

CVSS 10
CVE-2026-16232 Jul 22, 2026

Check Point SmartConsole auth bypass exploited (CVE-2026-16232) [PoC]

CVSS 9.1
CVE-2026-60137 Jul 17, 2026

WordPress SQLi exploited in the wild (CVE-2026-60137) [PoC]

CVSS 9.1
CVE-2026-63030 Jul 17, 2026

WordPress REST API unauth RCE (CVE-2026-63030) [PoC]

CVSS 9.8
CVE-2026-9198 Jul 17, 2026

Langflow unauthenticated RCE exploited in wild (CVE-2026-9198) [PoC]

CVSS 9.8 Langflow
CVE-2026-15409 Jul 14, 2026

SMA1000 Appliance SSRF exploited in wild (CVE-2026-15409) [PoC]

CVSS 10
CVE-2026-50522 Jul 14, 2026

SharePoint unauthenticated RCE actively exploited (CVE-2026-50522) [PoC]

CVSS 9.8 Microsoft Sharepoint Server
CVE-2026-56164 Jul 14, 2026

SharePoint privilege escalation exploited (CVE-2026-56164) [PoC]

CVSS 9.8 Microsoft Sharepoint Server
CVE-2026-58644 Jul 14, 2026

SharePoint unauthenticated RCE exploited (CVE-2026-58644)

CVSS 9.8 Microsoft Sharepoint Server
CVE-2026-56291 Jul 9, 2026

Balbooa Forms unauthenticated RCE exploited (CVE-2026-56291) [PoC]

CVSS 10 Balbooa Forms
CVE-2026-34038 Jul 6, 2026

Coolify RCE leaks secrets (CVE-2026-34038) [PoC]

CVSS 9.9
CVE-2026-48282 Jun 30, 2026

ColdFusion RCE exploited in wild (CVE-2026-48282) [PoC]

CVSS 10 Adobe Coldfusion
CVE-2026-58138 Jun 30, 2026

Orkes Conductor unauth RCE (CVE-2026-58138) [PoC]

CVSS 9.8
CVE-2026-56290 Jun 29, 2026

Page Builder CK unauth RCE exploited (CVE-2026-56290) [PoC]

CVSS 10 Joomlack Page Builder Ck
CVE-2026-48908 Jun 20, 2026

SP Page Builder unauth file upload (CVE-2026-48908) [PoC]

CVSS 10 Ollyo Sp Page Builder
CVE-2026-48939 Jun 20, 2026

iCagenda file upload unauth RCE (CVE-2026-48939) [PoC]

CVSS 10 Joomlic Icagenda
CVE-2026-12569 Jun 18, 2026

Windchill RCE exploited in the wild (CVE-2026-12569)

CVSS 9.3
CVE-2026-48558 Jun 12, 2026

SimpleHelp OIDC auth bypass actively exploited (CVE-2026-48558) [PoC]

CVSS 10
CVE-2026-35273 Jun 11, 2026

PeopleSoft Enterprise unauth takeover (CVE-2026-35273) [PoC]

CVSS 9.8 Oracle Peoplesoft Enterprise Peopletools
CVE-2026-10520 Jun 9, 2026

Ivanti Sentry RCE actively exploited (CVE-2026-10520) [PoC]

CVSS 10
CVE-2026-25089 Jun 9, 2026

FortiSandbox unauth RCE (CVE-2026-25089) [PoC]

CVSS 9.8
CVE-2026-50751 Jun 8, 2026

Remote Access VPN bypass exploited in wild (CVE-2026-50751) [PoC]

CVSS 9.3
CVE-2026-48907 Jun 5, 2026

JCE Editor unauth RCE exploited (CVE-2026-48907) [PoC]

CVSS 10
CVE-2026-8037 Jun 4, 2026

Progress ADC exploited for unauthenticated RCE (CVE-2026-8037) [PoC]

CVSS 9.8 Progress Connection Manager For Objectscale, Progress Ecs Connection Manager, Progress Loadmaster
CVE-2026-46817 May 28, 2026

Oracle E-Business Suite takeover (CVE-2026-46817) [PoC]

CVSS 9.8 Oracle E-Business Suite
CVE-2026-44590 May 27, 2026

Sherlock leaks CI tokens via command inj (CVE-2026-44590) [PoC]

CVSS 9.3
CVE-2026-48027 May 27, 2026

Nx Console supply chain attack actively exploited (CVE-2026-48027)

CVSS 9.8 Nx Console
CVE-2026-45247 May 26, 2026

Mirasvit FPC Warmer RCE exploited in wild (CVE-2026-45247) [PoC]

CVSS 9.8
CVE-2026-48172 May 21, 2026

LiteSpeed cPanel privilege escalation (CVE-2026-48172) [PoC]

CVSS 10
CVE-2026-8398 May 15, 2026

DAEMON Tools Lite supply chain attack (CVE-2026-8398)

CVSS 9.8
CVE-2026-20182 May 14, 2026

Catalyst SD-WAN bypass grants admin access (CVE-2026-20182) [PoC]

CVSS 10
CVE-2026-0257 May 13, 2026

PAN-OS GlobalProtect auth bypass (CVE-2026-0257) [PoC]

CVSS 9.1 Paloaltonetworks Pan-Os, Paloaltonetworks Prisma Access
CVE-2026-42945 May 13, 2026

NGINX Plus heap overflow, unauth (CVE-2026-42945) [PoC]

CVSS 9.2
CVE-2026-45321 May 12, 2026

TanStack npm packages leak credentials (CVE-2026-45321) [PoC]

CVSS 9.6 Tanstack Tanstack\\/Arktype-Adapter, Tanstack Tanstack\\/Eslint-Plugin-Router, Tanstack Tanstack\\/Eslint-Plugin-Start, Tanstack Tanstack\\/History, Tanstack Tanstack\\/Nitro-V2-Vite-Plugin
CVE-2021-47932 May 10, 2026

WordPress TheCartPress creates admin accounts (CVE-2021-47932)

CVSS 9.8
CVE-2021-47933 May 10, 2026

WordPress MStore API unauth RCE (CVE-2021-47933)

CVSS 9.8
CVE-2021-47936 May 10, 2026

OpenCATS unauthenticated RCE (CVE-2021-47936)

CVSS 9.8
CVE-2026-6722 May 10, 2026

PHP SOAP unauthenticated RCE (CVE-2026-6722)

CVSS 9.5
CVE-2026-37431 May 8, 2026

Beauty Parlour SQLi reads database (CVE-2026-37431)

CVSS 9.8
CVE-2026-41070 May 8, 2026

openvpn-auth-oauth2 bypasses SSO auth (CVE-2026-41070)

CVSS 10
CVE-2026-41497 May 8, 2026

PraisonAI RCE, no auth needed (CVE-2026-41497)

CVSS 9.8 Praison Praisonai
CVE-2026-41500 May 8, 2026

electerm unauth command injection (CVE-2026-41500)

CVSS 9.8 Electerm Project Electerm
CVE-2026-41501 May 8, 2026

electerm unauthenticated RCE (CVE-2026-41501)

CVSS 9.8 Electerm Project Electerm
CVE-2026-41512 May 8, 2026

ai-scanner RCE via JavaScript injection (CVE-2026-41512)

CVSS 9.9
CVE-2026-41574 May 8, 2026

Nhost account takeover via OAuth (CVE-2026-41574)

CVSS 9.3
Browse all advisories

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.