Search
34,854 CVEs · Critical severity
CVEs (34,854, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 34,854 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-37003 | CRITICAL | 9.8 | 2026-08-27 | Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and ShellTools components pass unsanitized, LLM-generated … | |
| CVE-2026-35869 | CRITICAL | 9.8 | 2026-08-27 | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0. This flaw occurs due to insuffi… | |
| CVE-2026-35868 | CRITICAL | 9.8 | 2026-08-27 | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4. This flaw occurs due to ins… | |
| CVE-2026-30612 | CRITICAL | 9.8 | 2026-08-27 | An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbit… | |
| CVE-2026-19092 | CRITICAL | Patched | 9.8 | 2026-08-27 | The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to i… |
| CVE-2026-81735 | CRITICAL | 10.0 | 2026-08-27 | startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound th… | |
| CVE-2026-81707 | CRITICAL | Patched | 9.8 | 2026-08-27 | openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint… |
| CVE-2026-81702 | CRITICAL | Patched | 9.8 | 2026-08-27 | openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identi… |
| CVE-2026-81701 | CRITICAL | Patched | 9.8 | 2026-08-27 | openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirect… |
| CVE-2026-81700 | CRITICAL | Patched | 9.8 | 2026-08-27 | openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VA… |
| CVE-2026-81098 | CRITICAL | 9.1 | 2026-08-27 | The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path wit… | |
| CVE-2026-81096 | CRITICAL | 10.0 | 2026-08-27 | ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor to… | |
| CVE-2026-81094 | CRITICAL | 9.1 | 2026-08-27 | The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/… | |
| CVE-2026-75357 | CRITICAL | 9.8 | 2026-08-27 | An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili-bridge.js components. | |
| CVE-2026-57499 | CRITICAL | Patched | 9.1 | 2026-08-27 | Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows an authentic… |
| CVE-2026-26897 | CRITICAL | 9.8 | 2026-08-27 | An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain sensitive information and execute arbitrary code via… | |
| CVE-2026-16279 | CRITICAL | 9.3 | 2026-08-27 | An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gai… | |
| CVE-2026-74233 | CRITICAL | Patched | 9.8 | 2026-08-27 | Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware … |
| CVE-2026-74232 | CRITICAL | Patched | 9.8 | 2026-08-27 | Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-762… |
| CVE-2026-78292 | CRITICAL | 9.8 | 2026-08-27 | Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions. | |
| CVE-2026-78288 | CRITICAL | 9.3 | 2026-08-27 | Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions. | |
| CVE-2026-78286 | CRITICAL | 9.8 | 2026-08-27 | Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions. | |
| CVE-2026-78274 | CRITICAL | 9.1 | 2026-08-27 | Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions. | |
| CVE-2026-78260 | CRITICAL | 9.3 | 2026-08-27 | Unauthenticated SQL Injection in Epayco <= 8.4.6 versions. | |
| CVE-2026-59354 | CRITICAL | Patched | 9.6 | 2026-08-27 | In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint p… |