Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

34,865 CVEs · Critical severity

CVEs (34,865, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 301–325 of 34,865 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-81098 CRITICAL 9.1 2026-08-27 The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path wit…
CVE-2026-81096 CRITICAL 10.0 2026-08-27 ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor to…
CVE-2026-81094 CRITICAL 9.1 2026-08-27 The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/…
CVE-2026-81032 CRITICAL 9.8 2026-08-26 NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind …
CVE-2026-8094 CRITICAL Patched 9.8 2026-05-07 Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.
CVE-2026-8091 CRITICAL Patched 9.8 2026-05-07 Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10…
CVE-2026-80726 CRITICAL 9.3 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page Explicitly clear role.inva…
CVE-2026-80725 CRITICAL 9.8 2026-08-29 In the Linux kernel, the following vulnerability has been resolved: net: gro: properly validate BIG TCP aggregation criteria When GRO attempts to aggregate packets beyond…
CVE-2026-80714 CRITICAL 9.8 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: ipvs: do not propagate one-packet flag to synced conns Synced connections can be created before their …
CVE-2026-80694 CRITICAL 9.8 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller mtk_handle_irq_rx expects…
CVE-2026-80693 CRITICAL 9.3 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: idpf: bound interrupt-vector register fill to the allocated array idpf_get_reg_intr_vecs() fills the c…
CVE-2026-80684 CRITICAL 9.3 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix NULL dereference on AIBV allocation failure The airq_iv_create() can return NULL o…
CVE-2026-80681 CRITICAL 9.8 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: vxlan: re-fetch eth header after route_shortcircuit() Before route_shortcircuit(), the eth header poin…
CVE-2026-80674 CRITICAL 9.8 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: ntfs: validate resident attribute lists and harden the validator A base inode's $ATTRIBUTE_LIST is san…
CVE-2026-80673 CRITICAL 9.8 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() When resolving an attribu…
CVE-2026-80671 CRITICAL 9.3 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: perf sched: Fix register_pid() overflow, strcpy, and BUG_ON register_pid() has several issues when pro…
CVE-2026-80670 CRITICAL 9.1 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: perf tools: Use perf_env__get_cpu_topology() in machine__resolve() machine__resolve() accesses env->cp…
CVE-2026-80668 CRITICAL 9.8 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use conntrack GC to reap expectations This patch replaces the timer AP…
CVE-2026-80634 CRITICAL 9.8 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag The DEV_PATH_BR_VLAN_UNTAG case …
CVE-2026-80630 CRITICAL 9.8 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen Whene…
CVE-2026-80617 CRITICAL 9.8 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix foe_check_time allocation size foe_check_time is declared as u16 pointer but was allo…
CVE-2026-80612 CRITICAL 9.8 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: net: lwtunnel: Drop skb metadata before LWT encapsulation skb metadata is meant for passing informatio…
CVE-2026-80609 CRITICAL 9.8 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: qede: fix out-of-bounds check for cqe->len_list[] Move index check before element access.
CVE-2026-80603 CRITICAL 9.1 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read parse_dcc() treats data_end as an inc…
CVE-2026-80600 CRITICAL 9.8 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: acquire ARP hw source only after skb realloc The pskb_may_pull() called by batadv_get…