CRITICAL CVSS 9.9 CVE-2026-46918 2026-08-23

Critical Vulnerability in Oracle E-Business Suite Products (CVE-2026-46918)

A critical vulnerability (CVE-2026-46918) allows low-privileged attackers to take over Oracle Process Manufacturing Product Development and Oracle E-Business Suite via HTTP. CVSS 9.9, affecting versions 12.2.3-12.2.15.

Read full advisory →
CRITICAL CVSS 9.9 CVE-2026-40747 2026-08-23

Critical Vulnerability in Ecommerce Zone Allows Arbitrary File Upload (CVE-2026-40747)

A critical vulnerability in Ecommerce Zone versions <= 0.9.7 allows attackers to perform arbitrary file uploads via subscriber accounts, enabling remote code execution. This poses a severe risk to systems using the affected platform.

Read full advisory →
CRITICAL CVSS 9.9 CVE-2026-52806 2026-08-23

Critical Remote Code Execution Vulnerability in Gogs (CVE-2026-52806)

A critical RCE vulnerability in Gogs allows authenticated users to execute arbitrary code on the server via a crafted pull request. Fixed in 0.14.3. CVSS 9.9.

Read full advisory →
CRITICAL CVSS 9.9 CVE-2026-45499 2026-08-22

Critical SSRF Vulnerability in Azure OpenAI (CVE-2026-45499)

A critical server-side request forgery vulnerability in Azure OpenAI allows authorized attackers to elevate privileges over a network. This affects the azure_openai platform with a CVSS score of 9.9.

Read full advisory →
CRITICAL CVSS 9.9 CVE-2026-39589 2026-08-22

Critical Vulnerability in Webenvo Allows Arbitrary File Upload (CVE-2026-39589)

A critical vulnerability in Webenvo versions up to 0.0.6 allows attackers to upload arbitrary files, leading to potential system compromise. Affected users should apply the latest security patches immediately.

Read full advisory →
CRITICAL CVSS 9.9 CVE-2026-56058 2026-08-22

Critical Vulnerability in Quform Plugin Allows Arbitrary File Upload (CVE-2026-56058)

A critical vulnerability in Quform plugin for WordPress allows attackers to upload arbitrary files, leading to potential code execution. Affected versions are Quform <= 2.23.0. Immediate patching is advised.

Read full advisory →
CRITICAL CVSS 9.9 CVE-2026-40749 2026-08-22

Critical Vulnerability in Charity Zone Platform Allows Arbitrary File Upload (CVE-2026-40749)

A critical vulnerability in Charity Zone Platform versions 1.1.1 and below allows attackers to upload arbitrary files, posing a significant risk to system integrity and data security.

Read full advisory →
CRITICAL CVSS 9.9 CVE-2026-40783 2026-08-22

Critical RCE Vulnerability in Blocksy Companion Pro (CVE-2026-40783)

A critical remote code execution vulnerability exists in Blocksy Companion Pro versions 2.1.37 and below, affecting WordPress platforms. This allows attackers to execute arbitrary code remotely, posing a severe security risk.

Read full advisory →
CRITICAL CVSS 9.9 CVE-2026-56274 2026-08-22

Critical OS Command Injection Vulnerability in Flowise (CVE-2026-56274)

Flowise versions prior to 3.1.2 are affected by multiple OS command injection vulnerabilities in the Custom MCP Server feature. Attackers can execute arbitrary commands on the host, posing a critical risk to systems using this platform.

Read full advisory →
CRITICAL CVSS 9.9 CVE-2026-54310 2026-08-22

Critical SQL Injection Vulnerability in n8n (CVE-2026-54310)

A critical SQL injection vulnerability in n8n allows authenticated users to execute arbitrary SQL commands. Affected versions are prior to 2.25.7 and 2.26.2. Users are advised to upgrade to the patched versions.

Read full advisory →
CRITICAL CVSS 10.0 CVE-2026-61539 2026-08-22

Critical Code Execution Vulnerability in Xinference (CVE-2026-61539)

A critical vulnerability in Xinference allows remote code execution via malicious Llama3 tool calls. Affected versions: 2.5.0 and earlier. CVSS 10.0. Immediate patching required.

Read full advisory →
CRITICAL CVSS 9.9 CVE-2026-48781 2026-08-22

Critical Vulnerability in Postiz Allows Session Impersonation (CVE-2026-48781)

A critical vulnerability in Postiz versions prior to 2.21.8 allows authenticated users to forge admin sessions. This enables full access to all instance data and social media accounts. Immediate patching is required.

Read full advisory →
← Newer Page 4 of 13 Older →