Search
13,088 CVEs
CVEs (13,088, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 13,088 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-80612 | CRITICAL | 9.8 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: net: lwtunnel: Drop skb metadata before LWT encapsulation skb metadata is meant for passing informatio… | |
| CVE-2026-80617 | CRITICAL | 9.8 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix foe_check_time allocation size foe_check_time is declared as u16 pointer but was allo… | |
| CVE-2026-80609 | CRITICAL | 9.8 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: qede: fix out-of-bounds check for cqe->len_list[] Move index check before element access. | |
| CVE-2026-80600 | CRITICAL | 9.8 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: acquire ARP hw source only after skb realloc The pskb_may_pull() called by batadv_get… | |
| CVE-2026-76581 | CRITICAL | 9.8 | 2026-08-28 | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HM… | |
| CVE-2026-78032 | CRITICAL | 9.8 | 2026-08-28 | SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege. | |
| CVE-2026-82082 | CRITICAL | 9.8 | 2026-08-28 | NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server. | |
| CVE-2026-78239 | CRITICAL | 9.8 | 2026-08-28 | Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that shoul… | |
| CVE-2026-76943 | CRITICAL | 9.8 | 2026-08-28 | Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command exe… | |
| CVE-2026-76179 | CRITICAL | 9.8 | 2026-08-28 | An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are ins… | |
| CVE-2026-75337 | CRITICAL | 9.8 | 2026-08-28 | The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The user-controlled path is concatenated to the preview ro… | |
| CVE-2026-73125 | CRITICAL | 9.8 | 2026-08-28 | Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attac… | |
| CVE-2026-71187 | CRITICAL | 9.8 | 2026-08-28 | The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and by… | |
| CVE-2026-69658 | CRITICAL | 9.8 | 2026-08-28 | MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device imperson… | |
| CVE-2026-59313 | CRITICAL | Patched | 9.8 | 2026-08-27 | Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Fr… |
| CVE-2026-37071 | CRITICAL | 9.8 | 2026-08-27 | Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' pe… | |
| CVE-2026-37072 | CRITICAL | 9.8 | 2026-08-27 | Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php. | |
| CVE-2026-37003 | CRITICAL | 9.8 | 2026-08-27 | Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and ShellTools components pass unsanitized, LLM-generated … | |
| CVE-2026-37004 | CRITICAL | 9.8 | 2026-08-27 | BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafte… | |
| CVE-2026-37006 | CRITICAL | 9.8 | 2026-08-27 | A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Conte… | |
| CVE-2026-37007 | CRITICAL | 9.8 | 2026-08-27 | A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via malicious path traversal sequences in the filename argument. | |
| CVE-2026-35868 | CRITICAL | 9.8 | 2026-08-27 | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4. This flaw occurs due to ins… | |
| CVE-2026-35869 | CRITICAL | 9.8 | 2026-08-27 | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0. This flaw occurs due to insuffi… | |
| CVE-2026-30612 | CRITICAL | 9.8 | 2026-08-27 | An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbit… | |
| CVE-2026-19092 | CRITICAL | Patched | 9.8 | 2026-08-27 | The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to i… |