Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

78,575 CVEs

CVEs (78,575, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 51–75 of 78,575 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-61539 CRITICAL Patched 10.0 2026-08-21 Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output t…
CVE-2026-69502 CRITICAL 10.0 2026-08-21 Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69555 CRITICAL 10.0 2026-08-20 Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69836 CRITICAL 10.0 2026-08-20 Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
CVE-2026-65816 CRITICAL 10.0 2026-08-20 Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-65801 CRITICAL 10.0 2026-08-20 Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-65770 CRITICAL 10.0 2026-08-20 Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute…
CVE-2026-22306 CRITICAL Patched 10.0 2026-08-19 Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Oz…
CVE-2026-20357 CRITICAL 10.0 2026-08-19 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review…
CVE-2026-20358 CRITICAL 10.0 2026-08-19 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review…
CVE-2026-20315 CRITICAL 10.0 2026-08-19 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security …
CVE-2026-20317 CRITICAL 10.0 2026-08-19 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security …
CVE-2026-20030 CRITICAL 10.0 2026-08-19 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review…
CVE-2026-75949 NONE &mdash; 2026-08-19 Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_pat&hellip;
CVE-2026-74803 NONE &mdash; 2026-08-19 Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type fa&hellip;
CVE-2026-67364 NONE &mdash; 2026-08-19 Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The&hellip;
CVE-2026-18051 CRITICAL Patched 10.0 2026-08-19 The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write&hellip;
CVE-2026-76008 CRITICAL 10.0 2026-08-19 A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This &hellip;
CVE-2026-70921 CRITICAL 10.0 2026-08-18 Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easil&hellip;
CVE-2026-70880 CRITICAL 10.0 2026-08-18 Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 1&hellip;
CVE-2026-61241 CRITICAL 10.0 2026-08-18 Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 1&hellip;
CVE-2026-75784 CRITICAL 10.0 2026-08-18 A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP H&hellip;
CVE-2026-73343 CRITICAL 10.0 2026-08-18 Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
CVE-2026-75874 CRITICAL Patched 10.0 2026-08-18 Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 15&hellip;
CVE-2026-74253 NONE Patched &mdash; 2026-08-17 Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0 - Regular Labs Sourcerer before 16.0.0 processes {sou&hellip;