Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

34,865 CVEs · Critical severity

CVEs (34,865, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 126–150 of 34,865 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-86190 CRITICAL 9.1 2026-09-05 WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and li…
CVE-2026-86189 CRITICAL 9.8 2026-09-05 WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a cal…
CVE-2026-86184 CRITICAL Patched 9.8 2026-09-05 Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user …
CVE-2026-86167 CRITICAL 9.9 2026-09-06 A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation…
CVE-2026-86165 CRITICAL 9.8 2026-09-06 A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argu…
CVE-2026-86153 CRITICAL 9.1 2026-09-06 A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation lead…
CVE-2026-86152 CRITICAL 10.0 2026-09-06 A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. …
CVE-2026-86151 CRITICAL 9.1 2026-09-06 A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Mana…
CVE-2026-86149 CRITICAL 9.1 2026-09-05 A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument inte…
CVE-2026-86148 CRITICAL 9.1 2026-09-05 A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipu…
CVE-2026-86124 CRITICAL 9.8 2026-09-05 AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. At…
CVE-2026-86121 CRITICAL Patched 9.8 2026-09-05 Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthe…
CVE-2026-8605 CRITICAL 9.8 2026-05-19 In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.
CVE-2026-8603 CRITICAL 9.8 2026-05-19 In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.
CVE-2026-8602 CRITICAL 9.1 2026-05-19 In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA syst…
CVE-2026-8598 CRITICAL 9.1 2026-05-20 An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information …
CVE-2026-8580 CRITICAL Patched 9.6 2026-05-14 Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium securit…
CVE-2026-85696 CRITICAL 9.8 2026-09-04 SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper esc…
CVE-2026-85695 CRITICAL 9.4 2026-09-04 FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and p…
CVE-2026-85688 CRITICAL 9.8 2026-09-04 TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and …
CVE-2026-85684 CRITICAL 9.1 2026-09-04 marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attac…
CVE-2026-85672 CRITICAL 9.8 2026-09-04 zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated uns…
CVE-2026-85667 CRITICAL 9.1 2026-09-04 xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into t…
CVE-2026-85663 CRITICAL 9.8 2026-09-04 Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation. Unauthenticated attackers ca…
CVE-2026-85661 CRITICAL 9.8 2026-09-04 excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can s…