Search
34,854 CVEs · Critical severity
CVEs (34,854, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 34,854 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-85506 | CRITICAL | Patched | 9.8 | 2026-09-04 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-syst… |
| CVE-2026-85504 | CRITICAL | Patched | 9.8 | 2026-09-04 | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malfo… |
| CVE-2026-11613 | CRITICAL | 9.8 | 2026-09-04 | The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter paramet… | |
| CVE-2026-85148 | CRITICAL | 9.8 | 2026-09-04 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely … | |
| CVE-2026-85146 | CRITICAL | 9.8 | 2026-09-04 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account creden… | |
| CVE-2026-85440 | CRITICAL | 9.8 | 2026-09-03 | MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling that allows remote attackers to write arbitrary data … | |
| CVE-2026-85438 | CRITICAL | 9.8 | 2026-09-03 | MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used a… | |
| CVE-2026-85437 | CRITICAL | 9.8 | 2026-09-03 | MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust attacker-controlled length fields without validation. A… | |
| CVE-2026-85435 | CRITICAL | 9.1 | 2026-09-03 | MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shor… | |
| CVE-2026-85434 | CRITICAL | 9.1 | 2026-09-03 | MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with … | |
| CVE-2026-85433 | CRITICAL | 9.8 | 2026-09-03 | MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. At… | |
| CVE-2026-85430 | CRITICAL | 9.1 | 2026-09-03 | MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attack… | |
| CVE-2026-85428 | CRITICAL | 9.8 | 2026-09-03 | MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Att… | |
| CVE-2026-85426 | CRITICAL | 9.8 | 2026-09-03 | MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into clie… | |
| CVE-2026-85425 | CRITICAL | 9.8 | 2026-09-03 | MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsanitized text to a shell command. Attackers can … | |
| CVE-2026-85424 | CRITICAL | 9.8 | 2026-09-03 | MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privil… | |
| CVE-2026-83711 | CRITICAL | 10.0 | 2026-09-03 | Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-80098 | CRITICAL | 9.3 | 2026-09-03 | Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-70352 | CRITICAL | 10.0 | 2026-09-03 | Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-62916 | CRITICAL | 9.1 | 2026-09-03 | Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-85224 | CRITICAL | 9.1 | 2026-09-03 | A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executin… | |
| CVE-2026-85223 | CRITICAL | 9.9 | 2026-09-03 | A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Pe… | |
| CVE-2026-85222 | CRITICAL | 9.1 | 2026-09-03 | A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component… | |
| CVE-2026-85061 | CRITICAL | Patched | 10.0 | 2026-09-03 | MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap… |
| CVE-2026-85050 | CRITICAL | 9.6 | 2026-09-03 | Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTM… |