Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

13,088 CVEs

CVEs (13,088, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 326–350 of 13,088 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-85437 CRITICAL 9.8 2026-09-03 MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust attacker-controlled length fields without validation. A…
CVE-2026-85438 CRITICAL 9.8 2026-09-03 MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used a…
CVE-2026-85440 CRITICAL 9.8 2026-09-03 MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling that allows remote attackers to write arbitrary data …
CVE-2026-85433 CRITICAL 9.8 2026-09-03 MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. At…
CVE-2026-85424 CRITICAL 9.8 2026-09-03 MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privil…
CVE-2026-85425 CRITICAL 9.8 2026-09-03 MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsanitized text to a shell command. Attackers can …
CVE-2026-85426 CRITICAL 9.8 2026-09-03 MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into clie…
CVE-2026-85428 CRITICAL 9.8 2026-09-03 MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Att…
CVE-2026-85391 CRITICAL 9.8 2026-09-03 Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attack…
CVE-2026-82526 CRITICAL 9.8 2026-09-03 R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name pa…
CVE-2026-84814 CRITICAL 9.8 2026-09-03 Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
CVE-2026-84834 CRITICAL 9.8 2026-09-03 Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
CVE-2026-84238 CRITICAL 9.8 2026-09-03 Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.
CVE-2026-84753 CRITICAL 9.8 2026-09-03 Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
CVE-2026-85181 CRITICAL 9.8 2026-09-03 CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can&hellip;
CVE-2026-85109 CRITICAL 9.8 2026-09-03 A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing &hellip;
CVE-2026-85154 CRITICAL 9.8 2026-09-03 WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator&hellip;
CVE-2026-19117 CRITICAL 9.8 2026-09-02 Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects &hellip;
CVE-2026-20279 CRITICAL 9.8 2026-09-02 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security &hellip;
CVE-2026-20274 CRITICAL 9.8 2026-09-02 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security &hellip;
CVE-2026-20212 CRITICAL 9.8 2026-09-02 A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with&nbsp;root privilege&hellip;
CVE-2026-53611 CRITICAL Patched 9.8 2026-09-02 Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute /&hellip;
CVE-2025-9314 CRITICAL 9.8 2026-09-02 The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component
CVE-2026-84795 CRITICAL Patched 9.8 2026-09-02 Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a de&hellip;
CVE-2026-81294 CRITICAL 9.8 2026-09-02 Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.