CRITICAL CVSS 10.0 CVE-2026-75874 2026-08-21

Critical Sandbox Escape Vulnerability in Remote Settings Client (CVE-2026-75874)

A critical sandbox escape vulnerability in the Remote Settings Client component affects Firefox, Thunderbird, and related libraries. This issue allows arbitrary code execution and was resolved in version 154 of affected software.

Read full advisory →
CRITICAL CVSS 10.0 CVE-2026-20315 2026-08-20

Cisco Secure Workload Vulnerability Allows Unauthorized Access (CVE-2026-20315)

A critical vulnerability in Cisco Secure Workload allows unauthorized access due to improper access control. This issue, with a CVSS score of 10.0, affects the platform and requires immediate mitigation.

Read full advisory →
CRITICAL CVSS 10.0 CVE-2026-20317 2026-08-20

Critical Authentication Vulnerability in Cisco Secure Workload (CVE-2026-20317)

A critical authentication vulnerability (CVE-2026-20317) with a CVSS score of 10.0 affects Cisco Secure Workload. This issue allows unauthorized access due to improper authentication mechanisms, requiring immediate mitigation.

Read full advisory →
CRITICAL CVSS 10.0 CVE-2026-76008 2026-08-20

Critical Remote Code Execution Vulnerability in Comfast CF-N1-S (CVE-2026-76008)

A critical vulnerability in Comfast CF-N1-S 2.6.0.1 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the get_para_from_uri function.

Read full advisory →
CRITICAL CVSS 10.0 CVE-2026-73343 2026-08-20

Critical RCE Vulnerability in WP Compress Plugin (CVE-2026-73343)

Unauthenticated Remote Code Execution (RCE) vulnerability in WP Compress plugin versions below 7.20.01 allows attackers to execute arbitrary code on affected WordPress installations.

Read full advisory →
CRITICAL CVSS 10.0 CVE-2026-61241 2026-08-19

Critical LDAP Server Vulnerability in Oracle Internet Directory (CVE-2026-61241)

A critical vulnerability in Oracle Internet Directory's LDAP server allows unauthenticated remote attackers to take control. Affects versions 12.2.1.4.0 and 14.1.2.1.0. Immediate patching required due to high exploitability and severe impact.

Read full advisory →
CRITICAL CVSS 10.0 CVE-2026-70880 2026-08-19

Critical Remote Code Execution Vulnerability in Oracle Hyperion (CVE-2026-70880)

A critical unauthenticated remote code execution vulnerability (CVE-2026-70880) affects Oracle Hyperion Data Relationship Management 11.2.25.0.000, enabling attackers to take full control of affected systems. Immediate patching is required to mitigate this high-severity threat.

Read full advisory →
CRITICAL CVSS 10.0 CVE-2026-70921 2026-08-19

Critical Vulnerability in Oracle Hyperion Financial Management (CVE-2026-70921)

A critical vulnerability in Oracle Hyperion Financial Management allows unauthenticated attackers to manipulate critical data. CVSS score 10.0. Immediate patching required.

Read full advisory →
CRITICAL CVSS 10.0 CVE-2026-75784 2026-08-19

Critical Stack-Based Buffer Overflow in TRENDnet TEW-WLC100 (CVE-2026-75784)

A critical stack-based buffer overflow vulnerability in TRENDnet TEW-WLC100 1v2.07b01 allows remote code execution via manipulated HTTP headers. Public exploits are available.

Read full advisory →
CRITICAL CVSS 10.0 CVE-2026-74843 2026-08-19

Critical Remote Code Execution Vulnerability in Wavlink Devices (CVE-2026-74843)

A critical remote code execution vulnerability (CVE-2026-74843) affects Wavlink WN531P3 and WN535M1 devices due to a stack-based buffer overflow in the export_pingortrace.cgi CGI script. Exploitation allows remote attackers to execute arbitrary code. Immediate mitigation is required.

Read full advisory →
CRITICAL CVSS 10.0 CVE-2026-19977 2026-08-19

Critical Authentication Bypass Vulnerability in EFM ipTIME A3004T (CVE-2026-19977)

A critical authentication bypass flaw in EFM ipTIME A3004T 14.19.0 allows remote attackers to exploit improper session validation. Public exploits exist, and the vendor has not provided a fix.

Read full advisory →
CRITICAL CVSS 10.0 CVE-2026-73678 2026-08-19

Critical Remote Code Execution Vulnerability in MindsDB Platform (CVE-2026-73678)

An unauthenticated remote code execution vulnerability in MindsDB 26.1.0 and earlier allows attackers to execute arbitrary OS commands via crafted API requests. Immediate patching is required to mitigate this critical risk.

Read full advisory →
← Newer Page 7 of 13 Older →