Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 326–350 of 2,372 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84326 | HIGH | Patched | 8.8 | 2026-09-02 | Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromi… |
| CVE-2026-84482 | HIGH | 8.8 | 2026-09-01 | WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate refe… | |
| CVE-2026-76851 | HIGH | Patched | 8.8 | 2026-09-01 | A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance. Insufficient network isola… |
| CVE-2026-73782 | HIGH | Patched | 8.8 | 2026-09-01 | A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulne… |
| CVE-2026-73750 | HIGH | 8.8 | 2026-09-01 | Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabil… | |
| CVE-2026-73751 | HIGH | 8.8 | 2026-09-01 | An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying opera… | |
| CVE-2026-73752 | HIGH | Patched | 8.8 | 2026-09-01 | An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitra… |
| CVE-2026-73753 | HIGH | 8.8 | 2026-09-01 | Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying … | |
| CVE-2026-71981 | HIGH | Patched | 8.8 | 2026-09-01 | Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted … |
| CVE-2026-73702 | HIGH | Patched | 8.8 | 2026-09-01 | A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user t… |
| CVE-2026-73703 | HIGH | Patched | 8.8 | 2026-09-01 | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a stored cross-site scri… |
| CVE-2026-73704 | HIGH | Patched | 8.8 | 2026-09-01 | A command sanitization bypass exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escal… |
| CVE-2026-73705 | HIGH | Patched | 8.8 | 2026-09-01 | An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to escalate privileges. Successf… |
| CVE-2026-72649 | HIGH | Patched | 8.8 | 2026-09-01 | Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially … |
| CVE-2026-51974 | HIGH | 8.8 | 2026-09-01 | An eval() injection vulnerability in the get_list function in modules/meta_parser.py in lllyasviel Fooocus 2.1.854 through 2.5.5 allows remote attackers to execute arbitrar… | |
| CVE-2026-19591 | HIGH | 8.8 | 2026-09-01 | OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser… | |
| CVE-2026-58566 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation o… | |
| CVE-2026-84268 | HIGH | 8.8 | 2026-09-01 | A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the … | |
| CVE-2026-84202 | HIGH | 8.8 | 2026-09-01 | ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can cra… | |
| CVE-2026-79682 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary … | |
| CVE-2026-58567 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitr… | |
| CVE-2026-10195 | HIGH | 8.8 | 2026-09-01 | The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 8.0.1. This is due to insufficient input sanitization of the FFmpe… | |
| CVE-2026-79686 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass … | |
| CVE-2026-58569 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit … | |
| CVE-2026-18630 | HIGH | 8.8 | 2026-09-01 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Managemen… |