Search
13,088 CVEs
CVEs (13,088, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 13,088 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18210 | CRITICAL | Patched | 9.8 | 2026-09-01 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and T… |
| CVE-2026-84140 | CRITICAL | Patched | 9.8 | 2026-09-01 | Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-84141 | CRITICAL | Patched | 9.8 | 2026-09-01 | Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-84142 | CRITICAL | Patched | 9.8 | 2026-09-01 | Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enoug… |
| CVE-2026-84143 | CRITICAL | Patched | 9.8 | 2026-09-01 | Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another secur… |
| CVE-2026-84133 | CRITICAL | Patched | 9.8 | 2026-09-01 | Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-84134 | CRITICAL | Patched | 9.8 | 2026-09-01 | Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-84135 | CRITICAL | Patched | 9.8 | 2026-09-01 | Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155. |
| CVE-2026-84129 | CRITICAL | Patched | 9.8 | 2026-09-01 | Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-51741 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a craft… | |
| CVE-2026-51744 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronizati… | |
| CVE-2026-51747 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh heartbeat information toward … | |
| CVE-2026-18765 | CRITICAL | 9.8 | 2026-09-01 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This … | |
| CVE-2026-18550 | CRITICAL | 9.8 | 2026-09-01 | The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to i… | |
| CVE-2026-75865 | CRITICAL | 9.8 | 2026-09-01 | The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing… | |
| CVE-2026-82226 | CRITICAL | 9.8 | 2026-08-31 | Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions. | |
| CVE-2026-79408 | CRITICAL | 9.8 | 2026-08-31 | An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt… | |
| CVE-2026-38577 | CRITICAL | 9.8 | 2026-08-31 | Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access. | |
| CVE-2026-51738 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset the device configuration and reboot … | |
| CVE-2026-51740 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a craf… | |
| CVE-2026-51733 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending … | |
| CVE-2026-51734 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh slave update coordination v… | |
| CVE-2026-51728 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the UploadFirmwareFile function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to upload a crafted firmware image via sen… | |
| CVE-2026-51724 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smart QoS rules via sending a crafte… | |
| CVE-2026-76133 | CRITICAL | 9.8 | 2026-08-31 | The affected Ebyte product uses a deprecated hashing algorithm in an authentication-related operation. Under conditions where an attacker can manipulate or predict the… |