Search
3,684 CVEs · Critical severity
CVEs (3,684, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 276–300 of 3,684 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-82695 | CRITICAL | 10.0 | 2026-08-31 | A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation … | |
| CVE-2026-82694 | CRITICAL | 10.0 | 2026-08-31 | A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manip… | |
| CVE-2026-82693 | CRITICAL | 10.0 | 2026-08-31 | A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executin… | |
| CVE-2026-82692 | CRITICAL | 9.9 | 2026-08-31 | A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the a… | |
| CVE-2026-82691 | CRITICAL | 9.1 | 2026-08-31 | A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the file /cgi-bin/… | |
| CVE-2026-82690 | CRITICAL | 9.1 | 2026-08-31 | A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. This manip… | |
| CVE-2026-82689 | CRITICAL | 9.9 | 2026-08-31 | A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the… | |
| CVE-2026-82688 | CRITICAL | 9.1 | 2026-08-31 | A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vo… | |
| CVE-2026-49003 | CRITICAL | 9.6 | 2026-08-31 | Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring module to crash and become paralyzed; simultaneously, th… | |
| CVE-2026-82874 | CRITICAL | 9.9 | 2026-08-31 | ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allow… | |
| CVE-2026-82872 | CRITICAL | 9.1 | 2026-08-31 | ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspac… | |
| CVE-2026-82870 | CRITICAL | 9.6 | 2026-08-31 | ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in… | |
| CVE-2026-82860 | CRITICAL | Patched | 9.8 | 2026-08-31 | @hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail. Attackers can craft admin-equiv… |
| CVE-2026-82859 | CRITICAL | 9.8 | 2026-08-31 | hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM bounda… | |
| CVE-2026-82858 | CRITICAL | Patched | 9.8 | 2026-08-31 | @hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated… |
| CVE-2026-82857 | CRITICAL | 9.8 | 2026-08-31 | hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles with… | |
| CVE-2026-82856 | CRITICAL | Patched | 9.8 | 2026-08-31 | @hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can use ForAnyValue:Stri… |
| CVE-2026-82855 | CRITICAL | Patched | 9.8 | 2026-08-31 | @hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppr… |
| CVE-2026-82854 | CRITICAL | Patched | 9.8 | 2026-08-31 | Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a … |
| CVE-2026-58574 | CRITICAL | 9.8 | 2026-08-31 | Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interfac… | |
| CVE-2026-82616 | CRITICAL | 9.9 | 2026-08-31 | A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the arg… | |
| CVE-2026-82593 | CRITICAL | 9.9 | 2026-08-31 | A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgr… | |
| CVE-2026-82592 | CRITICAL | 9.9 | 2026-08-30 | A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endp… | |
| CVE-2026-82542 | CRITICAL | 10.0 | 2026-08-30 | A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component B… | |
| CVE-2026-82539 | CRITICAL | 9.1 | 2026-08-30 | A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. … |