Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 30,217 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-60730 | CRITICAL | 9.9 | 2026-08-18 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0… | |
| CVE-2026-60702 | CRITICAL | 9.9 | 2026-08-18 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.… | |
| CVE-2026-75877 | CRITICAL | 9.9 | 2026-08-18 | A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function SystemNetworkChanged/SystemDDNSChanged/SystemEmailChanged/SystemFTPChanged/w… | |
| CVE-2026-55166 | CRITICAL | Patched | 9.9 | 2026-08-18 | Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restrict… |
| CVE-2026-66627 | CRITICAL | 9.9 | 2026-08-18 | Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a throu… | |
| CVE-2026-32474 | CRITICAL | 9.9 | 2026-08-18 | Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. | |
| CVE-2026-32444 | CRITICAL | 9.9 | 2026-08-18 | Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. | |
| CVE-2026-32463 | CRITICAL | 9.9 | 2026-08-18 | Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. | |
| CVE-2026-75851 | CRITICAL | Patched | 9.9 | 2026-08-18 | ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an… |
| CVE-2026-75843 | CRITICAL | Patched | 9.9 | 2026-08-18 | ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute Java… |
| CVE-2026-66795 | CRITICAL | 9.9 | 2026-08-17 | A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not … | |
| CVE-2026-65974 | CRITICAL | Patched | 9.9 | 2026-08-17 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe sa… |
| CVE-2026-47686 | CRITICAL | Patched | 9.9 | 2026-08-17 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and Ag… |
| CVE-2026-66792 | CRITICAL | 9.9 | 2026-08-17 | A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscr… | |
| CVE-2026-19961 | CRITICAL | 9.9 | 2026-08-16 | A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the arg… | |
| CVE-2026-19959 | CRITICAL | 9.9 | 2026-08-16 | A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argume… | |
| CVE-2026-72493 | CRITICAL | 9.9 | 2026-08-15 | In the Linux kernel, the following vulnerability has been resolved: net: serialize netif_running() check in enqueue_to_backlog() Syzbot reported a KASAN slab-use-after-fr… | |
| CVE-2026-17186 | CRITICAL | Patched | 9.9 | 2026-08-14 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command. |
| CVE-2026-19681 | CRITICAL | Patched | 9.9 | 2026-08-14 | An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially … |
| CVE-2026-19682 | CRITICAL | Patched | 9.9 | 2026-08-14 | A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlyin… |
| CVE-2026-19626 | CRITICAL | Patched | 9.9 | 2026-08-14 | A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issu… |
| CVE-2026-72841 | CRITICAL | 9.9 | 2026-08-13 | luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary file… | |
| CVE-2026-72842 | CRITICAL | 9.9 | 2026-08-13 | luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper au… | |
| CVE-2026-73656 | CRITICAL | Patched | 9.9 | 2026-08-13 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls … |
| CVE-2026-73602 | CRITICAL | Patched | 9.9 | 2026-08-13 | Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment lo… |