Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

13,088 CVEs

CVEs (13,088, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 451–475 of 13,088 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-80612 CRITICAL 9.8 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: net: lwtunnel: Drop skb metadata before LWT encapsulation skb metadata is meant for passing informatio…
CVE-2026-80617 CRITICAL 9.8 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix foe_check_time allocation size foe_check_time is declared as u16 pointer but was allo…
CVE-2026-80609 CRITICAL 9.8 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: qede: fix out-of-bounds check for cqe->len_list[] Move index check before element access.
CVE-2026-80600 CRITICAL 9.8 2026-08-28 In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: acquire ARP hw source only after skb realloc The pskb_may_pull() called by batadv_get…
CVE-2026-76581 CRITICAL 9.8 2026-08-28 The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HM…
CVE-2026-78032 CRITICAL 9.8 2026-08-28 SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege.
CVE-2026-82082 CRITICAL 9.8 2026-08-28 NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.
CVE-2026-78239 CRITICAL 9.8 2026-08-28 Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that shoul…
CVE-2026-76943 CRITICAL 9.8 2026-08-28 Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command exe…
CVE-2026-76179 CRITICAL 9.8 2026-08-28 An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are ins…
CVE-2026-75337 CRITICAL 9.8 2026-08-28 The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The user-controlled path is concatenated to the preview ro…
CVE-2026-73125 CRITICAL 9.8 2026-08-28 Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attac…
CVE-2026-71187 CRITICAL 9.8 2026-08-28 The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and by…
CVE-2026-69658 CRITICAL 9.8 2026-08-28 MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device imperson…
CVE-2026-59313 CRITICAL Patched 9.8 2026-08-27 Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Fr…
CVE-2026-37071 CRITICAL 9.8 2026-08-27 Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' pe…
CVE-2026-37072 CRITICAL 9.8 2026-08-27 Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php.
CVE-2026-37003 CRITICAL 9.8 2026-08-27 Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and ShellTools components pass unsanitized, LLM-generated …
CVE-2026-37004 CRITICAL 9.8 2026-08-27 BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafte&hellip;
CVE-2026-37006 CRITICAL 9.8 2026-08-27 A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Conte&hellip;
CVE-2026-37007 CRITICAL 9.8 2026-08-27 A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via malicious path traversal sequences in the filename argument.
CVE-2026-35868 CRITICAL 9.8 2026-08-27 A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4. This flaw occurs due to ins&hellip;
CVE-2026-35869 CRITICAL 9.8 2026-08-27 A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0. This flaw occurs due to insuffi&hellip;
CVE-2026-30612 CRITICAL 9.8 2026-08-27 An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbit&hellip;
CVE-2026-19092 CRITICAL Patched 9.8 2026-08-27 The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to i&hellip;