Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,217 CVEs

CVEs (30,217, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 351–375 of 30,217 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-60730 CRITICAL 9.9 2026-08-18 Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0…
CVE-2026-60702 CRITICAL 9.9 2026-08-18 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.…
CVE-2026-75877 CRITICAL 9.9 2026-08-18 A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function SystemNetworkChanged/SystemDDNSChanged/SystemEmailChanged/SystemFTPChanged/w…
CVE-2026-55166 CRITICAL Patched 9.9 2026-08-18 Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restrict…
CVE-2026-66627 CRITICAL 9.9 2026-08-18 Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a throu…
CVE-2026-32474 CRITICAL 9.9 2026-08-18 Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.
CVE-2026-32444 CRITICAL 9.9 2026-08-18 Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
CVE-2026-32463 CRITICAL 9.9 2026-08-18 Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
CVE-2026-75851 CRITICAL Patched 9.9 2026-08-18 ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an&hellip;
CVE-2026-75843 CRITICAL Patched 9.9 2026-08-18 ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute Java&hellip;
CVE-2026-66795 CRITICAL 9.9 2026-08-17 A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not &hellip;
CVE-2026-65974 CRITICAL Patched 9.9 2026-08-17 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe sa&hellip;
CVE-2026-47686 CRITICAL Patched 9.9 2026-08-17 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and Ag&hellip;
CVE-2026-66792 CRITICAL 9.9 2026-08-17 A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscr&hellip;
CVE-2026-19961 CRITICAL 9.9 2026-08-16 A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the arg&hellip;
CVE-2026-19959 CRITICAL 9.9 2026-08-16 A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argume&hellip;
CVE-2026-72493 CRITICAL 9.9 2026-08-15 In the Linux kernel, the following vulnerability has been resolved: net: serialize netif_running() check in enqueue_to_backlog() Syzbot reported a KASAN slab-use-after-fr&hellip;
CVE-2026-17186 CRITICAL Patched 9.9 2026-08-14 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.
CVE-2026-19681 CRITICAL Patched 9.9 2026-08-14 An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially &hellip;
CVE-2026-19682 CRITICAL Patched 9.9 2026-08-14 A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlyin&hellip;
CVE-2026-19626 CRITICAL Patched 9.9 2026-08-14 A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issu&hellip;
CVE-2026-72841 CRITICAL 9.9 2026-08-13 luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary file&hellip;
CVE-2026-72842 CRITICAL 9.9 2026-08-13 luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper au&hellip;
CVE-2026-73656 CRITICAL Patched 9.9 2026-08-13 Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls &hellip;
CVE-2026-73602 CRITICAL Patched 9.9 2026-08-13 Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment lo&hellip;