Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

34,865 CVEs · Critical severity

CVEs (34,865, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 426–450 of 34,865 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-7834 CRITICAL 9.8 2026-05-05 A security vulnerability has been detected in EFM ipTIME NAS1dual 1.5.24. This issue affects the function get_csrf_whites of the file /cgi/advanced/misc_main.cgi. Such mani…
CVE-2026-78329 CRITICAL Patched 9.8 2026-08-24 Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.11.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4…
CVE-2026-78328 CRITICAL 9.1 2026-09-04 A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileg…
CVE-2026-78327 CRITICAL 9.1 2026-09-04 An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Manageme…
CVE-2026-78292 CRITICAL 9.8 2026-08-27 Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
CVE-2026-78288 CRITICAL 9.3 2026-08-27 Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
CVE-2026-78286 CRITICAL 9.8 2026-08-27 Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
CVE-2026-78274 CRITICAL 9.1 2026-08-27 Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
CVE-2026-78267 CRITICAL 9.8 2026-08-24 Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
CVE-2026-78265 CRITICAL 9.8 2026-08-24 Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
CVE-2026-78262 CRITICAL 9.8 2026-08-24 Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
CVE-2026-78260 CRITICAL 9.3 2026-08-27 Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.
CVE-2026-78239 CRITICAL 9.8 2026-08-28 Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that shoul&hellip;
CVE-2026-78234 CRITICAL 9.9 2026-09-08 A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client cert&hellip;
CVE-2026-7823 CRITICAL 9.8 2026-05-05 A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of &hellip;
CVE-2026-78211 CRITICAL 9.8 2026-08-24 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through a&hellip;
CVE-2026-78207 CRITICAL 9.4 2026-08-24 exceljs through 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note &hellip;
CVE-2026-78183 CRITICAL 9.8 2026-08-23 DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the string + 1, which is the size of the bare numeric &hellip;
CVE-2026-78169 CRITICAL 9.9 2026-08-24 A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HT&hellip;
CVE-2026-78168 CRITICAL 9.8 2026-08-24 A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Hand&hellip;
CVE-2026-78167 CRITICAL 10.0 2026-08-24 A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. Th&hellip;
CVE-2026-78155 CRITICAL 9.9 2026-08-23 privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
CVE-2026-7813 CRITICAL Patched 9.9 2026-05-11 Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules. Multiple endpoints fetch&hellip;
CVE-2026-7808 CRITICAL Patched 9.8 2026-08-23 justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentiall&hellip;
CVE-2026-78050 CRITICAL 9.9 2026-08-23 A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of th&hellip;