Search
12,997 CVEs
CVEs (12,997, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 12,997 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-74820 | NONE | Patched | — | 2026-08-27 | ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in ce… |
| CVE-2026-6876 | NONE | Patched | — | 2026-08-27 | ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could allow an unauthenticated user to exec… |
| CVE-2026-18886 | NONE | Patched | — | 2026-08-27 | ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated use… |
| CVE-2026-18885 | NONE | Patched | — | 2026-08-27 | ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in cert… |
| CVE-2026-81735 | CRITICAL | 10.0 | 2026-08-27 | startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound th… | |
| CVE-2026-81096 | CRITICAL | 10.0 | 2026-08-27 | ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor to… | |
| CVE-2026-65956 | NONE | Patched | — | 2026-08-26 | KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public routing bo… |
| CVE-2026-77554 | CRITICAL | 10.0 | 2026-08-26 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the … | |
| CVE-2026-77550 | CRITICAL | 10.0 | 2026-08-26 | A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass au… | |
| CVE-2026-77537 | CRITICAL | 10.0 | 2026-08-26 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on t… | |
| CVE-2026-79911 | CRITICAL | 10.0 | 2026-08-25 | A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi o… | |
| CVE-2026-76197 | CRITICAL | Patched | 10.0 | 2026-08-25 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in… |
| CVE-2026-76193 | CRITICAL | Patched | 10.0 | 2026-08-25 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current u… |
| CVE-2026-76195 | CRITICAL | Patched | 10.0 | 2026-08-25 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in… |
| CVE-2026-77998 | NONE | — | 2026-08-25 | Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with AD… | |
| CVE-2025-36939 | NONE | — | 2026-08-24 | Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a… | |
| CVE-2026-77995 | NONE | — | 2026-08-24 | Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – OIDC SSO < 1.2.2, Login with Keycloak OAuth Single… | |
| CVE-2026-78167 | CRITICAL | 10.0 | 2026-08-24 | A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. Th… | |
| CVE-2026-74705 | CRITICAL | 10.0 | 2026-08-22 | In the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel segmentation __skb_udp_tunnel_segment() gets the UDP heade… | |
| CVE-2026-74612 | CRITICAL | 10.0 | 2026-08-22 | In the Linux kernel, the following vulnerability has been resolved: veth: fix skb length accounting after XDP frag adjustment veth exposes non-linear skb fragments throug… | |
| CVE-2026-76604 | NONE | — | 2026-08-22 | Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable to the execution of user… | |
| CVE-2026-76605 | NONE | — | 2026-08-22 | Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2. | |
| CVE-2026-76606 | NONE | — | 2026-08-22 | Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2. | |
| CVE-2026-76607 | NONE | — | 2026-08-22 | Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2. | |
| CVE-2026-77946 | CRITICAL | 10.0 | 2026-08-22 | A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the comp… |