Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

13,088 CVEs

CVEs (13,088, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 226–250 of 13,088 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-19682 CRITICAL Patched 9.9 2026-08-14 A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlyin…
CVE-2026-19626 CRITICAL Patched 9.9 2026-08-14 A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issu…
CVE-2026-72841 CRITICAL 9.9 2026-08-13 luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary file…
CVE-2026-72842 CRITICAL 9.9 2026-08-13 luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper au…
CVE-2026-73656 CRITICAL Patched 9.9 2026-08-13 Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls …
CVE-2026-73602 CRITICAL Patched 9.9 2026-08-13 Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment lo…
CVE-2026-66898 CRITICAL 9.9 2026-08-12 A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup a…
CVE-2026-73268 CRITICAL 9.9 2026-08-12 A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject…
CVE-2026-73269 CRITICAL 9.9 2026-08-12 A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creatio…
CVE-2026-72508 CRITICAL 9.9 2026-08-12 A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to pe…
CVE-2026-63293 CRITICAL Patched 9.9 2026-08-12 A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archiv…
CVE-2026-63294 CRITICAL 9.9 2026-08-12 A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup arc…
CVE-2026-63296 CRITICAL 9.9 2026-08-12 An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to…
CVE-2026-63297 CRITICAL 9.9 2026-08-12 An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during…
CVE-2026-63298 CRITICAL 9.9 2026-08-12 An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configurat…
CVE-2026-63299 CRITICAL 9.9 2026-08-12 An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource lim…
CVE-2026-63300 CRITICAL 9.9 2026-08-12 An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permiss…
CVE-2026-62420 CRITICAL 9.9 2026-08-12 An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When …
CVE-2026-19656 CRITICAL 9.9 2026-08-12 ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissi…
CVE-2026-16860 CRITICAL Patched 9.9 2026-08-12 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.
CVE-2026-73294 CRITICAL Patched 9.9 2026-08-12 Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option…
CVE-2026-73263 CRITICAL Patched 9.9 2026-08-12 Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config…
CVE-2026-72526 CRITICAL 9.9 2026-08-12 A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom …
CVE-2026-48765 CRITICAL 9.9 2026-08-11 TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configu…
CVE-2026-72765 CRITICAL Patched 9.9 2026-08-11 n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission to create or modify workflows can…