Search
13,088 CVEs
CVEs (13,088, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 13,088 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-78657 | CRITICAL | 9.8 | 2026-09-02 | The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_file… | |
| CVE-2026-9055 | CRITICAL | 9.8 | 2026-09-02 | The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insuf… | |
| CVE-2026-84325 | CRITICAL | Patched | 9.8 | 2026-09-02 | Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictio… |
| CVE-2026-84480 | CRITICAL | 9.8 | 2026-09-01 | WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefi… | |
| CVE-2026-84637 | CRITICAL | Patched | 9.8 | 2026-09-01 | Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment… |
| CVE-2026-84372 | CRITICAL | Patched | 9.8 | 2026-09-01 | Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replicatio… |
| CVE-2023-54391 | CRITICAL | Patched | 9.8 | 2026-09-01 | Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers… |
| CVE-2026-73749 | CRITICAL | Patched | 9.8 | 2026-09-01 | Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulne… |
| CVE-2026-52111 | CRITICAL | 9.8 | 2026-09-01 | An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes authTokenKey | |
| CVE-2026-19593 | CRITICAL | 9.8 | 2026-09-01 | OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a reposito… | |
| CVE-2026-51934 | CRITICAL | 9.8 | 2026-09-01 | Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co., Ltd. Tenda A18 v.15.13.07.09 allows a remote attacker to execute arbitrary code via the fromSetCmdl… | |
| CVE-2026-51769 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to restart the cloud update check work… | |
| CVE-2026-51770 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS sett… | |
| CVE-2026-51767 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset pairing state and reboot the device… | |
| CVE-2026-78012 | CRITICAL | 9.8 | 2026-09-01 | An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generat… | |
| CVE-2026-51754 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state v… | |
| CVE-2026-51757 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflo… | |
| CVE-2026-51760 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity acro… | |
| CVE-2026-51762 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state an… | |
| CVE-2026-51763 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sen… | |
| CVE-2026-51764 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking … | |
| CVE-2026-51765 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor recor… | |
| CVE-2026-51750 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channe… | |
| CVE-2026-51751 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local … | |
| CVE-2026-18808 | CRITICAL | 9.8 | 2026-09-01 | Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This i… |