Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

34,865 CVEs · Critical severity

CVEs (34,865, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 376–400 of 34,865 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-73125 CRITICAL 9.8 2026-08-28 Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attac…
CVE-2026-71187 CRITICAL 9.8 2026-08-28 The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and by…
CVE-2026-69658 CRITICAL 9.8 2026-08-28 MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device imperson…
CVE-2026-50152 CRITICAL Patched 9.1 2026-08-28 Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fail…
CVE-2026-59313 CRITICAL Patched 9.8 2026-08-27 Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Fr…
CVE-2026-59283 CRITICAL Patched 9.1 2026-08-27 Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression c…
CVE-2026-37071 CRITICAL 9.8 2026-08-27 Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' pe…
CVE-2026-37072 CRITICAL 9.8 2026-08-27 Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php.
CVE-2026-37065 CRITICAL 9.1 2026-08-27 Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&action=update&remove=.
CVE-2026-37003 CRITICAL 9.8 2026-08-27 Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and ShellTools components pass unsanitized, LLM-generated …
CVE-2026-37004 CRITICAL 9.8 2026-08-27 BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafte&hellip;
CVE-2026-37006 CRITICAL 9.8 2026-08-27 A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Conte&hellip;
CVE-2026-37007 CRITICAL 9.8 2026-08-27 A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via malicious path traversal sequences in the filename argument.
CVE-2026-35868 CRITICAL 9.8 2026-08-27 A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4. This flaw occurs due to ins&hellip;
CVE-2026-35869 CRITICAL 9.8 2026-08-27 A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0. This flaw occurs due to insuffi&hellip;
CVE-2026-30612 CRITICAL 9.8 2026-08-27 An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbit&hellip;
CVE-2026-19092 CRITICAL Patched 9.8 2026-08-27 The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to i&hellip;
CVE-2026-81735 CRITICAL 10.0 2026-08-27 startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound th&hellip;
CVE-2026-81707 CRITICAL Patched 9.8 2026-08-27 openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint&hellip;
CVE-2026-81700 CRITICAL Patched 9.8 2026-08-27 openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VA&hellip;
CVE-2026-81701 CRITICAL Patched 9.8 2026-08-27 openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirect&hellip;
CVE-2026-81702 CRITICAL Patched 9.8 2026-08-27 openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identi&hellip;
CVE-2026-81098 CRITICAL 9.1 2026-08-27 The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path wit&hellip;
CVE-2026-81094 CRITICAL 9.1 2026-08-27 The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/&hellip;
CVE-2026-81096 CRITICAL 10.0 2026-08-27 ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor to&hellip;