Search
34,865 CVEs · Critical severity
CVEs (34,865, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 251–275 of 34,865 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-82858 | CRITICAL | Patched | 9.8 | 2026-08-31 | @hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated… |
| CVE-2026-82857 | CRITICAL | 9.8 | 2026-08-31 | hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles with… | |
| CVE-2026-82856 | CRITICAL | Patched | 9.8 | 2026-08-31 | @hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can use ForAnyValue:Stri… |
| CVE-2026-82855 | CRITICAL | Patched | 9.8 | 2026-08-31 | @hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppr… |
| CVE-2026-82854 | CRITICAL | Patched | 9.8 | 2026-08-31 | Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a … |
| CVE-2026-82695 | CRITICAL | 10.0 | 2026-08-31 | A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation … | |
| CVE-2026-82694 | CRITICAL | 10.0 | 2026-08-31 | A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manip… | |
| CVE-2026-82693 | CRITICAL | 10.0 | 2026-08-31 | A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executin… | |
| CVE-2026-82692 | CRITICAL | 9.9 | 2026-08-31 | A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the a… | |
| CVE-2026-82691 | CRITICAL | 9.1 | 2026-08-31 | A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the file /cgi-bin/… | |
| CVE-2026-82690 | CRITICAL | 9.1 | 2026-08-31 | A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. This manip… | |
| CVE-2026-82689 | CRITICAL | 9.9 | 2026-08-31 | A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the… | |
| CVE-2026-82688 | CRITICAL | 9.1 | 2026-08-31 | A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vo… | |
| CVE-2026-82616 | CRITICAL | 9.9 | 2026-08-31 | A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the arg… | |
| CVE-2026-82593 | CRITICAL | 9.9 | 2026-08-31 | A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgr… | |
| CVE-2026-82592 | CRITICAL | 9.9 | 2026-08-30 | A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endp… | |
| CVE-2026-82542 | CRITICAL | 10.0 | 2026-08-30 | A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component B… | |
| CVE-2026-82539 | CRITICAL | 9.1 | 2026-08-30 | A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. … | |
| CVE-2026-82526 | CRITICAL | 9.8 | 2026-09-03 | R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name pa… | |
| CVE-2026-82460 | CRITICAL | Patched | 9.8 | 2026-08-29 | Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization… |
| CVE-2026-82456 | CRITICAL | 10.0 | 2026-08-29 | argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Atta… | |
| CVE-2026-82454 | CRITICAL | 9.1 | 2026-08-29 | The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extrac… | |
| CVE-2026-82452 | CRITICAL | 9.8 | 2026-08-29 | rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures.… | |
| CVE-2026-82448 | CRITICAL | 9.8 | 2026-08-29 | Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. At… | |
| CVE-2026-82329 | CRITICAL | Patched | 9.8 | 2026-08-28 | JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative … |