Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 251–275 of 2,372 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86166 | HIGH | 8.8 | 2026-09-06 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server… | |
| CVE-2026-67277 | NONE | Patched | — | 2026-09-05 | RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start a… |
| CVE-2025-9049 | HIGH | 8.8 | 2026-09-05 | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_… | |
| CVE-2026-86177 | HIGH | Patched | 8.8 | 2026-09-05 | Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute … |
| CVE-2026-86169 | HIGH | 8.8 | 2026-09-05 | Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the sec… | |
| CVE-2026-81543 | HIGH | 8.8 | 2026-09-05 | The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capab… | |
| CVE-2026-77826 | HIGH | Patched | 8.8 | 2026-09-05 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, all… |
| CVE-2026-19887 | HIGH | 8.8 | 2026-09-05 | The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the… | |
| CVE-2026-52775 | HIGH | Patched | 8.8 | 2026-09-05 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::de… |
| CVE-2026-77393 | HIGH | 8.8 | 2026-09-04 | In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute g… | |
| CVE-2026-82712 | HIGH | 8.8 | 2026-09-04 | Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changi… | |
| CVE-2026-79423 | HIGH | 8.8 | 2026-09-04 | An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request. | |
| CVE-2026-82538 | HIGH | 8.8 | 2026-09-04 | ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is… | |
| CVE-2026-57161 | NONE | — | 2026-09-04 | PJSIP is a free and open source multimedia communication library written in C. Prior to commit acc03b5, a stack buffer overflow exists in PJSUA when processing Service-Rout… | |
| CVE-2026-57162 | NONE | — | 2026-09-04 | PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP/SDES media transport when… | |
| CVE-2026-57163 | NONE | — | 2026-09-04 | PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuTLS TLS backend when parsin… | |
| CVE-2026-18486 | HIGH | 8.8 | 2026-09-04 | IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper… | |
| CVE-2026-75169 | HIGH | 8.8 | 2026-09-04 | An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with Admin role to up… | |
| CVE-2026-75161 | HIGH | 8.8 | 2026-09-04 | An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Stan… | |
| CVE-2026-19298 | HIGH | 8.8 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process. | |
| CVE-2026-85623 | HIGH | 8.8 | 2026-09-04 | goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection. Attackers can distribute malicious recipes that execute … | |
| CVE-2026-85607 | HIGH | 8.8 | 2026-09-04 | Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/r… | |
| CVE-2026-18198 | HIGH | 8.8 | 2026-09-04 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN O… | |
| CVE-2026-85617 | HIGH | Patched | 8.8 | 2026-09-04 | snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside thei… |
| CVE-2026-85604 | HIGH | Patched | 8.8 | 2026-09-04 | Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes… |