Search
13,088 CVEs
CVEs (13,088, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 13,088 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-74843 | CRITICAL | 10.0 | 2026-08-17 | A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pi… | |
| CVE-2026-19977 | CRITICAL | 10.0 | 2026-08-17 | A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a … | |
| CVE-2026-74764 | NONE | — | 2026-08-15 | Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive member na… | |
| CVE-2026-74475 | CRITICAL | 10.0 | 2026-08-15 | In the Linux kernel, the following vulnerability has been resolved: vxlan: use neigh_ha_snapshot() in route_shortcircuit() The neighbour hardware address n->ha can be upd… | |
| CVE-2026-74309 | CRITICAL | 10.0 | 2026-08-15 | In the Linux kernel, the following vulnerability has been resolved: vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler Look up the IRQ index in oct_hw->irqs ins… | |
| CVE-2026-74279 | CRITICAL | 10.0 | 2026-08-15 | In the Linux kernel, the following vulnerability has been resolved: crypto: cavium/cpt - fix DMA cleanup using wrong loop index The sg_cleanup error path used list[i] ins… | |
| CVE-2026-74280 | CRITICAL | 10.0 | 2026-08-15 | In the Linux kernel, the following vulnerability has been resolved: crypto: marvell/octeontx - fix DMA cleanup using wrong loop index The sg_cleanup path used list[i] ins… | |
| CVE-2026-72421 | CRITICAL | 10.0 | 2026-08-15 | In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: Don't ignore error route in local/main tables. When CONFIG_IP_MULTIPLE_TABLES is enabled bu… | |
| CVE-2026-72407 | CRITICAL | 10.0 | 2026-08-15 | In the Linux kernel, the following vulnerability has been resolved: geneve: validate inner network offset in geneve_gro_complete() Even with both paths gated on gs->gro_h… | |
| CVE-2026-72408 | CRITICAL | 10.0 | 2026-08-15 | In the Linux kernel, the following vulnerability has been resolved: geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint geneve_gro_receive() reads the GRO hint… | |
| CVE-2026-73678 | CRITICAL | 10.0 | 2026-08-14 | MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary… | |
| CVE-2026-19188 | CRITICAL | 10.0 | 2026-08-14 | A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessib… | |
| CVE-2026-72811 | CRITICAL | Patched | 10.0 | 2026-08-14 | SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (t… |
| CVE-2026-72851 | CRITICAL | Patched | 10.0 | 2026-08-13 | Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-contro… |
| CVE-2026-61962 | CRITICAL | 10.0 | 2026-08-13 | Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions. | |
| CVE-2026-27544 | CRITICAL | 10.0 | 2026-08-13 | Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions. | |
| CVE-2026-59500 | CRITICAL | 10.0 | 2026-08-13 | : Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Prio… | |
| CVE-2026-15413 | CRITICAL | 10.0 | 2026-08-13 | The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ … | |
| CVE-2024-27253 | CRITICAL | 10.0 | 2026-08-12 | IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities. | |
| CVE-2026-73299 | CRITICAL | Patched | 10.0 | 2026-08-12 | Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies… |
| CVE-2026-67282 | NONE | — | 2026-08-12 | Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend l… | |
| CVE-2026-45618 | CRITICAL | 10.0 | 2026-08-11 | LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 pa… | |
| CVE-2026-71398 | CRITICAL | Patched | 10.0 | 2026-08-11 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An at… |
| CVE-2026-27302 | CRITICAL | Patched | 10.0 | 2026-08-11 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An at… |
| CVE-2026-48362 | CRITICAL | 10.0 | 2026-08-11 | ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code ex… |