Search
34,702 CVEs · Critical severity
EOL hidden · Show all products
CVEs (34,702, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 34,702 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-73125 | CRITICAL | 9.8 | 2026-08-28 | Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attac… | |
| CVE-2026-71187 | CRITICAL | 9.8 | 2026-08-28 | The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and by… | |
| CVE-2026-69658 | CRITICAL | 9.8 | 2026-08-28 | MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device imperson… | |
| CVE-2026-50152 | CRITICAL | Patched | 9.1 | 2026-08-28 | Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fail… |
| CVE-2026-59313 | CRITICAL | Patched | 9.8 | 2026-08-27 | Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Fr… |
| CVE-2026-59283 | CRITICAL | Patched | 9.1 | 2026-08-27 | Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression c… |
| CVE-2026-37072 | CRITICAL | 9.8 | 2026-08-27 | Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php. | |
| CVE-2026-37071 | CRITICAL | 9.8 | 2026-08-27 | Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' pe… | |
| CVE-2026-37065 | CRITICAL | 9.1 | 2026-08-27 | Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&action=update&remove=. | |
| CVE-2026-37007 | CRITICAL | 9.8 | 2026-08-27 | A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via malicious path traversal sequences in the filename argument. | |
| CVE-2026-37006 | CRITICAL | 9.8 | 2026-08-27 | A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Conte… | |
| CVE-2026-37004 | CRITICAL | 9.8 | 2026-08-27 | BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafte… | |
| CVE-2026-37003 | CRITICAL | 9.8 | 2026-08-27 | Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and ShellTools components pass unsanitized, LLM-generated … | |
| CVE-2026-35869 | CRITICAL | 9.8 | 2026-08-27 | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0. This flaw occurs due to insuffi… | |
| CVE-2026-35868 | CRITICAL | 9.8 | 2026-08-27 | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4. This flaw occurs due to ins… | |
| CVE-2026-30612 | CRITICAL | 9.8 | 2026-08-27 | An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbit… | |
| CVE-2026-19092 | CRITICAL | Patched | 9.8 | 2026-08-27 | The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to i… |
| CVE-2026-81735 | CRITICAL | 10.0 | 2026-08-27 | startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound th… | |
| CVE-2026-81707 | CRITICAL | Patched | 9.8 | 2026-08-27 | openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint… |
| CVE-2026-81702 | CRITICAL | Patched | 9.8 | 2026-08-27 | openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identi… |
| CVE-2026-81701 | CRITICAL | Patched | 9.8 | 2026-08-27 | openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirect… |
| CVE-2026-81700 | CRITICAL | Patched | 9.8 | 2026-08-27 | openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VA… |
| CVE-2026-81098 | CRITICAL | 9.1 | 2026-08-27 | The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path wit… | |
| CVE-2026-81096 | CRITICAL | 10.0 | 2026-08-27 | ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor to… | |
| CVE-2026-81094 | CRITICAL | 9.1 | 2026-08-27 | The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/… |