Search
13,088 CVEs
CVEs (13,088, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 13,088 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-81707 | CRITICAL | Patched | 9.8 | 2026-08-27 | openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint… |
| CVE-2026-81700 | CRITICAL | Patched | 9.8 | 2026-08-27 | openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VA… |
| CVE-2026-81701 | CRITICAL | Patched | 9.8 | 2026-08-27 | openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirect… |
| CVE-2026-81702 | CRITICAL | Patched | 9.8 | 2026-08-27 | openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identi… |
| CVE-2026-75357 | CRITICAL | 9.8 | 2026-08-27 | An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili-bridge.js components. | |
| CVE-2026-26897 | CRITICAL | 9.8 | 2026-08-27 | An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain sensitive information and execute arbitrary code via… | |
| CVE-2026-74233 | CRITICAL | Patched | 9.8 | 2026-08-27 | Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware … |
| CVE-2026-74232 | CRITICAL | Patched | 9.8 | 2026-08-27 | Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-762… |
| CVE-2026-78286 | CRITICAL | 9.8 | 2026-08-27 | Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions. | |
| CVE-2026-78292 | CRITICAL | 9.8 | 2026-08-27 | Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions. | |
| CVE-2026-32566 | CRITICAL | 9.8 | 2026-08-27 | Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. | |
| CVE-2026-47890 | CRITICAL | Patched | 9.8 | 2026-08-27 | Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Frame… |
| CVE-2026-47891 | CRITICAL | Patched | 9.8 | 2026-08-27 | A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 … |
| CVE-2026-47892 | CRITICAL | Patched | 9.8 | 2026-08-27 | A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framewor… |
| CVE-2026-47884 | CRITICAL | 9.8 | 2026-08-27 | Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view nam… | |
| CVE-2026-75330 | CRITICAL | 9.8 | 2026-08-26 | The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directl… | |
| CVE-2026-75336 | CRITICAL | 9.8 | 2026-08-26 | Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json. | |
| CVE-2026-75338 | CRITICAL | 9.8 | 2026-08-26 | disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/… | |
| CVE-2026-75329 | CRITICAL | 9.8 | 2026-08-26 | The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configurat… | |
| CVE-2026-75411 | CRITICAL | 9.8 | 2026-08-26 | JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class e… | |
| CVE-2026-75414 | CRITICAL | 9.8 | 2026-08-26 | In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability. | |
| CVE-2026-52103 | CRITICAL | 9.8 | 2026-08-26 | A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands… | |
| CVE-2026-75327 | CRITICAL | 9.8 | 2026-08-26 | In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability: | |
| CVE-2026-75334 | CRITICAL | 9.8 | 2026-08-26 | The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql parameter is stored in the t_report_sql_resource table t… | |
| CVE-2026-68000 | CRITICAL | 9.8 | 2026-08-26 | The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directly concatenated into the LIMIT clause of SQL through … |