Search
80,425 CVEs
CVEs (80,425, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 80,425 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-29128 | CRITICAL | 10.0 | 2026-03-05 | IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) that are owned by root bu… | |
| CVE-2026-20131 | CRITICAL | 10.0 | 2026-03-04 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute a… | |
| CVE-2026-20079 | CRITICAL | 10.0 | 2026-03-04 | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and … | |
| CVE-2026-28289 | CRITICAL | Patched | 10.0 | 2026-03-03 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows a… |
| CVE-2026-24898 | CRITICAL | Patched | 10.0 | 2026-03-03 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token disclosure vulnerability i… |
| CVE-2026-28409 | CRITICAL | Patched | 10.0 | 2026-02-27 | WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database … |
| CVE-2026-21718 | CRITICAL | Patched | 10.0 | 2026-02-27 | An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication requirement and achieve p… |
| CVE-2026-20127 | CRITICAL | Patched | 10.0 | 2026-02-25 | A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco… |
| CVE-2026-27597 | CRITICAL | Patched | 10.0 | 2026-02-25 | Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boundraries set by `@enclav… |
| CVE-2026-2776 | CRITICAL | Patched | 10.0 | 2026-02-24 | Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefo… |
| CVE-2026-2778 | CRITICAL | Patched | 10.0 | 2026-02-24 | Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, T… |
| CVE-2026-2768 | CRITICAL | Patched | 10.0 | 2026-02-24 | Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
| CVE-2026-2760 | CRITICAL | Patched | 10.0 | 2026-02-24 | Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8… |
| CVE-2026-2761 | CRITICAL | Patched | 10.0 | 2026-02-24 | Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
| CVE-2026-23693 | CRITICAL | 10.0 | 2026-02-23 | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-js… | |
| CVE-2026-27211 | CRITICAL | Patched | 10.0 | 2026-02-21 | Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. Versions 34.0 through 50.0 arevulnerable to arbitrary host file exfiltration (constrained by process priv… |
| CVE-2021-35402 | CRITICAL | Patched | 10.0 | 2026-02-20 | PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metacharacters in the ip parameter (for satellite_status). |
| CVE-2025-30411 | CRITICAL | 10.0 | 2026-02-20 | Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938… | |
| CVE-2025-30412 | CRITICAL | 10.0 | 2026-02-20 | Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938… | |
| CVE-2025-30416 | CRITICAL | 10.0 | 2026-02-20 | Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, … | |
| CVE-2026-2731 | NONE | — | 2026-02-19 | Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (<9.19.7 and <9.20.3) allows unauthenticated attackers to execute code via simp… | |
| CVE-2025-15586 | NONE | — | 2026-02-19 | OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw which if exploited can result in authentication bypass w… | |
| CVE-2026-22769 | CRITICAL | Patched | 10.0 | 2026-02-17 | Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remot… |
| CVE-2026-2577 | CRITICAL | 10.0 | 2026-02-16 | The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not require authentication for inco… | |
| CVE-2025-69770 | CRITICAL | 10.0 | 2026-02-13 | A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via uploading a crafted zip file. |