Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

12,997 CVEs

CVEs (12,997, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 26–50 of 12,997 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-74820 NONE Patched — 2026-08-27 ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in ce…
CVE-2026-6876 NONE Patched — 2026-08-27 ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could allow an unauthenticated user to exec…
CVE-2026-18886 NONE Patched — 2026-08-27 ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated use…
CVE-2026-18885 NONE Patched — 2026-08-27 ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in cert…
CVE-2026-81735 CRITICAL 10.0 2026-08-27 startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound th…
CVE-2026-81096 CRITICAL 10.0 2026-08-27 ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor to…
CVE-2026-65956 NONE Patched — 2026-08-26 KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public routing bo…
CVE-2026-77554 CRITICAL 10.0 2026-08-26 A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the …
CVE-2026-77550 CRITICAL 10.0 2026-08-26 A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass au…
CVE-2026-77537 CRITICAL 10.0 2026-08-26 A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on t…
CVE-2026-79911 CRITICAL 10.0 2026-08-25 A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi o…
CVE-2026-76197 CRITICAL Patched 10.0 2026-08-25 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in…
CVE-2026-76193 CRITICAL Patched 10.0 2026-08-25 Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current u…
CVE-2026-76195 CRITICAL Patched 10.0 2026-08-25 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in…
CVE-2026-77998 NONE &mdash; 2026-08-25 Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with AD&hellip;
CVE-2025-36939 NONE &mdash; 2026-08-24 Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a&hellip;
CVE-2026-77995 NONE &mdash; 2026-08-24 Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – OIDC SSO < 1.2.2, Login with Keycloak OAuth Single&hellip;
CVE-2026-78167 CRITICAL 10.0 2026-08-24 A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. Th&hellip;
CVE-2026-74705 CRITICAL 10.0 2026-08-22 In the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel segmentation __skb_udp_tunnel_segment() gets the UDP heade&hellip;
CVE-2026-74612 CRITICAL 10.0 2026-08-22 In the Linux kernel, the following vulnerability has been resolved: veth: fix skb length accounting after XDP frag adjustment veth exposes non-linear skb fragments throug&hellip;
CVE-2026-76604 NONE &mdash; 2026-08-22 Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable to the execution of user&hellip;
CVE-2026-76605 NONE &mdash; 2026-08-22 Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.
CVE-2026-76606 NONE &mdash; 2026-08-22 Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.
CVE-2026-76607 NONE &mdash; 2026-08-22 Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.
CVE-2026-77946 CRITICAL 10.0 2026-08-22 A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the comp&hellip;