Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

34,865 CVEs · Critical severity

CVEs (34,865, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 251–275 of 34,865 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-82858 CRITICAL Patched 9.8 2026-08-31 @hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated…
CVE-2026-82857 CRITICAL 9.8 2026-08-31 hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles with…
CVE-2026-82856 CRITICAL Patched 9.8 2026-08-31 @hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can use ForAnyValue:Stri…
CVE-2026-82855 CRITICAL Patched 9.8 2026-08-31 @hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppr…
CVE-2026-82854 CRITICAL Patched 9.8 2026-08-31 Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a …
CVE-2026-82695 CRITICAL 10.0 2026-08-31 A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation …
CVE-2026-82694 CRITICAL 10.0 2026-08-31 A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manip…
CVE-2026-82693 CRITICAL 10.0 2026-08-31 A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executin…
CVE-2026-82692 CRITICAL 9.9 2026-08-31 A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the a…
CVE-2026-82691 CRITICAL 9.1 2026-08-31 A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the file /cgi-bin/…
CVE-2026-82690 CRITICAL 9.1 2026-08-31 A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. This manip…
CVE-2026-82689 CRITICAL 9.9 2026-08-31 A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the…
CVE-2026-82688 CRITICAL 9.1 2026-08-31 A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vo…
CVE-2026-82616 CRITICAL 9.9 2026-08-31 A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the arg…
CVE-2026-82593 CRITICAL 9.9 2026-08-31 A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgr…
CVE-2026-82592 CRITICAL 9.9 2026-08-30 A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endp…
CVE-2026-82542 CRITICAL 10.0 2026-08-30 A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component B…
CVE-2026-82539 CRITICAL 9.1 2026-08-30 A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. …
CVE-2026-82526 CRITICAL 9.8 2026-09-03 R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name pa…
CVE-2026-82460 CRITICAL Patched 9.8 2026-08-29 Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization…
CVE-2026-82456 CRITICAL 10.0 2026-08-29 argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Atta…
CVE-2026-82454 CRITICAL 9.1 2026-08-29 The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extrac…
CVE-2026-82452 CRITICAL 9.8 2026-08-29 rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures.…
CVE-2026-82448 CRITICAL 9.8 2026-08-29 Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. At…
CVE-2026-82329 CRITICAL Patched 9.8 2026-08-28 JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative …