Search
2,281 CVEs
CVEs (2,281, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 2,281 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85428 | CRITICAL | 9.8 | 2026-09-03 | MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Att… | |
| CVE-2026-85391 | CRITICAL | 9.8 | 2026-09-03 | Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attack… | |
| CVE-2026-82526 | CRITICAL | 9.8 | 2026-09-03 | R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name pa… | |
| CVE-2026-84814 | CRITICAL | 9.8 | 2026-09-03 | Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions. | |
| CVE-2026-84834 | CRITICAL | 9.8 | 2026-09-03 | Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions. | |
| CVE-2026-84238 | CRITICAL | 9.8 | 2026-09-03 | Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions. | |
| CVE-2026-84753 | CRITICAL | 9.8 | 2026-09-03 | Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. | |
| CVE-2026-85181 | CRITICAL | 9.8 | 2026-09-03 | CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can… | |
| CVE-2026-85109 | CRITICAL | 9.8 | 2026-09-03 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing … | |
| CVE-2026-85154 | CRITICAL | 9.8 | 2026-09-03 | WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator… | |
| CVE-2026-19117 | CRITICAL | 9.8 | 2026-09-02 | Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects … | |
| CVE-2026-20279 | CRITICAL | 9.8 | 2026-09-02 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … | |
| CVE-2026-20274 | CRITICAL | 9.8 | 2026-09-02 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … | |
| CVE-2026-20212 | CRITICAL | 9.8 | 2026-09-02 | A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privilege… | |
| CVE-2026-53611 | CRITICAL | Patched | 9.8 | 2026-09-02 | Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute /… |
| CVE-2025-9314 | CRITICAL | 9.8 | 2026-09-02 | The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component | |
| CVE-2026-84795 | CRITICAL | Patched | 9.8 | 2026-09-02 | Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a de… |
| CVE-2026-81294 | CRITICAL | 9.8 | 2026-09-02 | Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions. | |
| CVE-2026-78657 | CRITICAL | 9.8 | 2026-09-02 | The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_file… | |
| CVE-2026-9055 | CRITICAL | 9.8 | 2026-09-02 | The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insuf… | |
| CVE-2026-84325 | CRITICAL | Patched | 9.8 | 2026-09-02 | Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictio… |
| CVE-2026-84480 | CRITICAL | 9.8 | 2026-09-01 | WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefi… | |
| CVE-2026-84637 | CRITICAL | Patched | 9.8 | 2026-09-01 | Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment… |
| CVE-2026-84372 | CRITICAL | Patched | 9.8 | 2026-09-01 | Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replicatio… |
| CVE-2023-54391 | CRITICAL | Patched | 9.8 | 2026-09-01 | Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers… |