Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

34,702 CVEs · Critical severity

EOL hidden · Show all products

CVEs (34,702, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 326–350 of 34,702 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-55511 CRITICAL Patched 9.1 2026-08-28 Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name …
CVE-2026-55248 CRITICAL Patched 9.1 2026-08-28 plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and 7.0.2, a member who can add an RSS portlet can set i…
CVE-2026-55247 CRITICAL Patched 9.1 2026-08-28 plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insuffici…
CVE-2026-54755 CRITICAL Patched 9.6 2026-08-28 Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain value…
CVE-2026-54754 CRITICAL Patched 9.6 2026-08-28 Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPe…
CVE-2026-54745 CRITICAL Patched 10.0 2026-08-28 Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthentica…
CVE-2026-51660 CRITICAL 9.1 2026-08-28 Incorrect access control in the getIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IP and port filtering rules vi…
CVE-2026-51657 CRITICAL 9.1 2026-08-28 Incorrect access control in the getSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain syslog-related configuration via sendi…
CVE-2026-51649 CRITICAL 9.1 2026-08-28 Incorrect access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain diagnostic configuration and ping l…
CVE-2026-51646 CRITICAL 9.1 2026-08-28 Incorrect access control in the getParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain parental-control rules via sending…
CVE-2026-51645 CRITICAL 9.8 2026-08-28 Incorrect access control in the getPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the administrative username via send…
CVE-2026-51643 CRITICAL 9.1 2026-08-28 Incorrect access control in the getNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain NTP configuration and current time data v…
CVE-2026-51636 CRITICAL 9.1 2026-08-28 Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi ACL rules via sending a craft…
CVE-2026-51628 CRITICAL 9.1 2026-08-28 Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to generate and retrieve a new WPS PIN …
CVE-2026-51626 CRITICAL 9.1 2026-08-28 Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS configuration, including the curr…
CVE-2026-51622 CRITICAL 9.1 2026-08-28 Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN configuration data via sending a craf…
CVE-2026-51611 CRITICAL 9.8 2026-08-28 Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force a reboot via sending a …
CVE-2026-82078 CRITICAL Patched 9.1 2026-08-28 An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver class…
CVE-2026-81578 CRITICAL Patched 9.8 2026-08-28 An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests t…
CVE-2026-37751 CRITICAL 9.8 2026-08-28 An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary comman…
CVE-2026-37236 CRITICAL 9.8 2026-08-28 grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowe…
CVE-2026-82244 CRITICAL Patched 9.1 2026-08-28 Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploadin…
CVE-2026-82222 CRITICAL 10.0 2026-08-28 Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.
CVE-2026-42007 CRITICAL Patched 9.1 2026-08-28 An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory conten…
CVE-2026-80714 CRITICAL 9.8 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: ipvs: do not propagate one-packet flag to synced conns Synced connections can be created before their …