Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

34,865 CVEs · Critical severity

CVEs (34,865, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 101–125 of 34,865 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-85425 CRITICAL 9.8 2026-09-03 MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsanitized text to a shell command. Attackers can …
CVE-2026-85426 CRITICAL 9.8 2026-09-03 MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into clie…
CVE-2026-85428 CRITICAL 9.8 2026-09-03 MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Att…
CVE-2026-70352 CRITICAL 10.0 2026-09-03 Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-80098 CRITICAL 9.3 2026-09-03 Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-83711 CRITICAL 10.0 2026-09-03 Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62916 CRITICAL 9.1 2026-09-03 Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-85223 CRITICAL 9.9 2026-09-03 A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Pe…
CVE-2026-85224 CRITICAL 9.1 2026-09-03 A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executin…
CVE-2026-85061 CRITICAL Patched 10.0 2026-09-03 MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap…
CVE-2026-85222 CRITICAL 9.1 2026-09-03 A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component…
CVE-2026-85050 CRITICAL 9.6 2026-09-03 Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTM…
CVE-2026-85047 CRITICAL 9.6 2026-09-03 Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside…
CVE-2026-85043 CRITICAL 9.1 2026-09-03 Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium …
CVE-2026-85042 CRITICAL 9.6 2026-09-03 Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromiu…
CVE-2026-85394 CRITICAL 9.1 2026-09-03 python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attacker…
CVE-2026-85391 CRITICAL 9.8 2026-09-03 Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attack…
CVE-2026-82526 CRITICAL 9.8 2026-09-03 R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name pa…
CVE-2026-58400 CRITICAL Patched 9.1 2026-09-03 GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is con…
CVE-2026-84813 CRITICAL 9.3 2026-09-03 Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.
CVE-2026-84814 CRITICAL 9.8 2026-09-03 Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
CVE-2026-84834 CRITICAL 9.8 2026-09-03 Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
CVE-2026-84768 CRITICAL 9.3 2026-09-03 Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.
CVE-2026-84238 CRITICAL 9.8 2026-09-03 Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.
CVE-2026-84753 CRITICAL 9.8 2026-09-03 Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.