Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 301–325 of 30,217 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48755 | CRITICAL | 9.9 | 2026-08-21 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injecti… | |
| CVE-2026-48769 | CRITICAL | 9.9 | 2026-08-21 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a … | |
| CVE-2026-48749 | CRITICAL | 9.9 | 2026-08-21 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; … | |
| CVE-2026-48750 | CRITICAL | 9.9 | 2026-08-21 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of … | |
| CVE-2026-48751 | CRITICAL | 9.9 | 2026-08-21 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for … | |
| CVE-2026-48752 | CRITICAL | 9.9 | 2026-08-21 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary … | |
| CVE-2026-48753 | CRITICAL | 9.9 | 2026-08-21 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbi… | |
| CVE-2026-77683 | CRITICAL | 9.9 | 2026-08-21 | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezo… | |
| CVE-2026-69851 | CRITICAL | 9.9 | 2026-08-20 | Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-68782 | CRITICAL | 9.9 | 2026-08-20 | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-68789 | CRITICAL | 9.9 | 2026-08-20 | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-63509 | CRITICAL | 9.9 | 2026-08-20 | Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-18835 | CRITICAL | Patched | 9.9 | 2026-08-20 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements u… |
| CVE-2026-67567 | CRITICAL | 9.9 | 2026-08-20 | A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), t… | |
| CVE-2026-77148 | CRITICAL | 9.9 | 2026-08-20 | A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET§ion=ptest_channel of the componen… | |
| CVE-2026-77022 | CRITICAL | 9.9 | 2026-08-20 | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_… | |
| CVE-2026-74014 | CRITICAL | 9.9 | 2026-08-20 | Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions. | |
| CVE-2026-74016 | CRITICAL | 9.9 | 2026-08-20 | Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions. | |
| CVE-2026-74018 | CRITICAL | 9.9 | 2026-08-20 | Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions. | |
| CVE-2026-73992 | CRITICAL | 9.9 | 2026-08-20 | Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions. | |
| CVE-2026-76589 | CRITICAL | 9.9 | 2026-08-19 | A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results i… | |
| CVE-2026-76590 | CRITICAL | 9.9 | 2026-08-19 | A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi.… | |
| CVE-2026-76584 | CRITICAL | 9.9 | 2026-08-19 | A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionality of the file /cgi-bin/admin/set_time.cgi of the co… | |
| CVE-2026-55089 | CRITICAL | Patched | 9.9 | 2026-08-19 | Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authorizes requests to /api/2/* in the authorization_code OA… |
| CVE-2026-70496 | CRITICAL | 9.9 | 2026-08-19 | A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write R… |