Search
208 CVEs · Critical severity
CVEs (208)
Showing 101–125 of 208
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-85426 | CRITICAL | 9.8 | 2026-09-03 | MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into clie… | |
| CVE-2026-85425 | CRITICAL | 9.8 | 2026-09-03 | MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsanitized text to a shell command. Attackers can … | |
| CVE-2026-85424 | CRITICAL | 9.8 | 2026-09-03 | MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privil… | |
| CVE-2026-83711 | CRITICAL | 10.0 | 2026-09-03 | Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-80098 | CRITICAL | 9.3 | 2026-09-03 | Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-70352 | CRITICAL | 10.0 | 2026-09-03 | Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-62916 | CRITICAL | 9.1 | 2026-09-03 | Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-85224 | CRITICAL | 9.1 | 2026-09-03 | A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executin… | |
| CVE-2026-85223 | CRITICAL | 9.9 | 2026-09-03 | A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Pe… | |
| CVE-2026-85222 | CRITICAL | 9.1 | 2026-09-03 | A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component… | |
| CVE-2026-85061 | CRITICAL | Patched | 10.0 | 2026-09-03 | MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap… |
| CVE-2026-85050 | CRITICAL | 9.6 | 2026-09-03 | Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTM… | |
| CVE-2026-85047 | CRITICAL | 9.6 | 2026-09-03 | Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside… | |
| CVE-2026-85043 | CRITICAL | 9.1 | 2026-09-03 | Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium … | |
| CVE-2026-85042 | CRITICAL | 9.6 | 2026-09-03 | Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromiu… | |
| CVE-2026-85394 | CRITICAL | 9.1 | 2026-09-03 | python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attacker… | |
| CVE-2026-85391 | CRITICAL | 9.8 | 2026-09-03 | Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attack… | |
| CVE-2026-82526 | CRITICAL | 9.8 | 2026-09-03 | R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name pa… | |
| CVE-2026-58400 | CRITICAL | Patched | 9.1 | 2026-09-03 | GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is con… |
| CVE-2026-84834 | CRITICAL | 9.8 | 2026-09-03 | Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions. | |
| CVE-2026-84814 | CRITICAL | 9.8 | 2026-09-03 | Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions. | |
| CVE-2026-84813 | CRITICAL | 9.3 | 2026-09-03 | Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions. | |
| CVE-2026-84768 | CRITICAL | 9.3 | 2026-09-03 | Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions. | |
| CVE-2026-84753 | CRITICAL | 9.8 | 2026-09-03 | Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. | |
| CVE-2026-84238 | CRITICAL | 9.8 | 2026-09-03 | Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions. |