Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,281 CVEs

CVEs (2,281, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 76–100 of 2,281 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-85428 CRITICAL 9.8 2026-09-03 MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Att…
CVE-2026-85391 CRITICAL 9.8 2026-09-03 Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attack…
CVE-2026-82526 CRITICAL 9.8 2026-09-03 R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name pa…
CVE-2026-84814 CRITICAL 9.8 2026-09-03 Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
CVE-2026-84834 CRITICAL 9.8 2026-09-03 Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
CVE-2026-84238 CRITICAL 9.8 2026-09-03 Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.
CVE-2026-84753 CRITICAL 9.8 2026-09-03 Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
CVE-2026-85181 CRITICAL 9.8 2026-09-03 CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can&hellip;
CVE-2026-85109 CRITICAL 9.8 2026-09-03 A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing &hellip;
CVE-2026-85154 CRITICAL 9.8 2026-09-03 WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator&hellip;
CVE-2026-19117 CRITICAL 9.8 2026-09-02 Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects &hellip;
CVE-2026-20279 CRITICAL 9.8 2026-09-02 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security &hellip;
CVE-2026-20274 CRITICAL 9.8 2026-09-02 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security &hellip;
CVE-2026-20212 CRITICAL 9.8 2026-09-02 A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with&nbsp;root privilege&hellip;
CVE-2026-53611 CRITICAL Patched 9.8 2026-09-02 Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute /&hellip;
CVE-2025-9314 CRITICAL 9.8 2026-09-02 The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component
CVE-2026-84795 CRITICAL Patched 9.8 2026-09-02 Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a de&hellip;
CVE-2026-81294 CRITICAL 9.8 2026-09-02 Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
CVE-2026-78657 CRITICAL 9.8 2026-09-02 The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_file&hellip;
CVE-2026-9055 CRITICAL 9.8 2026-09-02 The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insuf&hellip;
CVE-2026-84325 CRITICAL Patched 9.8 2026-09-02 Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictio&hellip;
CVE-2026-84480 CRITICAL 9.8 2026-09-01 WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefi&hellip;
CVE-2026-84637 CRITICAL Patched 9.8 2026-09-01 Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment&hellip;
CVE-2026-84372 CRITICAL Patched 9.8 2026-09-01 Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replicatio&hellip;
CVE-2023-54391 CRITICAL Patched 9.8 2026-09-01 Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers&hellip;