Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

34,691 CVEs · Critical severity

EOL hidden · Show all products

CVEs (34,691, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 51–75 of 34,691 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-75430 CRITICAL 9.8 2026-09-04 PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This all…
CVE-2026-31020 CRITICAL 9.8 2026-09-04 In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionalit…
CVE-2026-75431 CRITICAL 9.1 2026-09-04 PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code.
CVE-2026-75160 CRITICAL 9.1 2026-09-04 An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.
CVE-2026-44402 CRITICAL 9.8 2026-09-04 Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to …
CVE-2026-19274 CRITICAL 9.6 2026-09-04 IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently dest…
CVE-2026-18658 CRITICAL 9.8 2026-09-04 IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execut…
CVE-2026-85696 CRITICAL 9.8 2026-09-04 SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper esc…
CVE-2026-85695 CRITICAL 9.4 2026-09-04 FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and p…
CVE-2026-85688 CRITICAL 9.8 2026-09-04 TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and …
CVE-2026-85684 CRITICAL 9.1 2026-09-04 marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attac…
CVE-2026-85672 CRITICAL 9.8 2026-09-04 zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated uns…
CVE-2026-85667 CRITICAL 9.1 2026-09-04 xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into t…
CVE-2026-85663 CRITICAL 9.8 2026-09-04 Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation. Unauthenticated attackers ca…
CVE-2026-85661 CRITICAL 9.8 2026-09-04 excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can s…
CVE-2026-85184 CRITICAL Patched 9.1 2026-09-04 @fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolve…
CVE-2026-82923 CRITICAL 9.8 2026-09-04 The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to…
CVE-2026-85085 CRITICAL Patched 9.6 2026-09-04 The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to com…
CVE-2026-70403 CRITICAL 9.8 2026-09-04 XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.
CVE-2026-69657 CRITICAL 9.8 2026-09-04 XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device.
CVE-2026-62928 CRITICAL 9.8 2026-09-04 XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.
CVE-2026-15354 CRITICAL 9.8 2026-09-04 The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `sub…
CVE-2026-85509 CRITICAL Patched 9.8 2026-09-04 FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.
CVE-2026-85508 CRITICAL Patched 9.8 2026-09-04 ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell…
CVE-2026-85507 CRITICAL Patched 9.8 2026-09-04 ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).