Search
34,702 CVEs · Critical severity
EOL hidden · Show all products
CVEs (34,702, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 326–350 of 34,702 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-55511 | CRITICAL | Patched | 9.1 | 2026-08-28 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name … |
| CVE-2026-55248 | CRITICAL | Patched | 9.1 | 2026-08-28 | plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and 7.0.2, a member who can add an RSS portlet can set i… |
| CVE-2026-55247 | CRITICAL | Patched | 9.1 | 2026-08-28 | plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insuffici… |
| CVE-2026-54755 | CRITICAL | Patched | 9.6 | 2026-08-28 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain value… |
| CVE-2026-54754 | CRITICAL | Patched | 9.6 | 2026-08-28 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPe… |
| CVE-2026-54745 | CRITICAL | Patched | 10.0 | 2026-08-28 | Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthentica… |
| CVE-2026-51660 | CRITICAL | 9.1 | 2026-08-28 | Incorrect access control in the getIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IP and port filtering rules vi… | |
| CVE-2026-51657 | CRITICAL | 9.1 | 2026-08-28 | Incorrect access control in the getSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain syslog-related configuration via sendi… | |
| CVE-2026-51649 | CRITICAL | 9.1 | 2026-08-28 | Incorrect access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain diagnostic configuration and ping l… | |
| CVE-2026-51646 | CRITICAL | 9.1 | 2026-08-28 | Incorrect access control in the getParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain parental-control rules via sending… | |
| CVE-2026-51645 | CRITICAL | 9.8 | 2026-08-28 | Incorrect access control in the getPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the administrative username via send… | |
| CVE-2026-51643 | CRITICAL | 9.1 | 2026-08-28 | Incorrect access control in the getNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain NTP configuration and current time data v… | |
| CVE-2026-51636 | CRITICAL | 9.1 | 2026-08-28 | Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi ACL rules via sending a craft… | |
| CVE-2026-51628 | CRITICAL | 9.1 | 2026-08-28 | Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to generate and retrieve a new WPS PIN … | |
| CVE-2026-51626 | CRITICAL | 9.1 | 2026-08-28 | Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS configuration, including the curr… | |
| CVE-2026-51622 | CRITICAL | 9.1 | 2026-08-28 | Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN configuration data via sending a craf… | |
| CVE-2026-51611 | CRITICAL | 9.8 | 2026-08-28 | Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force a reboot via sending a … | |
| CVE-2026-82078 | CRITICAL | Patched | 9.1 | 2026-08-28 | An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver class… |
| CVE-2026-81578 | CRITICAL | Patched | 9.8 | 2026-08-28 | An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests t… |
| CVE-2026-37751 | CRITICAL | 9.8 | 2026-08-28 | An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary comman… | |
| CVE-2026-37236 | CRITICAL | 9.8 | 2026-08-28 | grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowe… | |
| CVE-2026-82244 | CRITICAL | Patched | 9.1 | 2026-08-28 | Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploadin… |
| CVE-2026-82222 | CRITICAL | 10.0 | 2026-08-28 | Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1. | |
| CVE-2026-42007 | CRITICAL | Patched | 9.1 | 2026-08-28 | An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory conten… |
| CVE-2026-80714 | CRITICAL | 9.8 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: ipvs: do not propagate one-packet flag to synced conns Synced connections can be created before their … |