Search
13,088 CVEs
CVEs (13,088, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 126–150 of 13,088 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-82689 | CRITICAL | 9.9 | 2026-08-31 | A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the… | |
| CVE-2026-82874 | CRITICAL | 9.9 | 2026-08-31 | ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allow… | |
| CVE-2026-82616 | CRITICAL | 9.9 | 2026-08-31 | A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the arg… | |
| CVE-2026-82593 | CRITICAL | 9.9 | 2026-08-31 | A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgr… | |
| CVE-2026-82592 | CRITICAL | 9.9 | 2026-08-30 | A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endp… | |
| CVE-2026-19295 | CRITICAL | Patched | 9.9 | 2026-08-28 | IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted … |
| CVE-2026-18527 | CRITICAL | 9.9 | 2026-08-28 | IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI compon… | |
| CVE-2026-55565 | CRITICAL | Patched | 9.9 | 2026-08-28 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExp… |
| CVE-2026-55634 | CRITICAL | Patched | 9.9 | 2026-08-28 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/def… |
| CVE-2026-77553 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privile… | |
| CVE-2026-77546 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Comm… | |
| CVE-2026-77547 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Comm… | |
| CVE-2026-77548 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Com… | |
| CVE-2026-77543 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Comm… | |
| CVE-2026-77534 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate… | |
| CVE-2026-77536 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate… | |
| CVE-2026-77533 | CRITICAL | 9.9 | 2026-08-26 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Com… | |
| CVE-2026-65093 | CRITICAL | Patched | 9.9 | 2026-08-25 | NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution,… |
| CVE-2026-65083 | CRITICAL | Patched | 9.9 | 2026-08-25 | NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exp… |
| CVE-2026-32559 | CRITICAL | 9.9 | 2026-08-24 | Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions. | |
| CVE-2026-66897 | CRITICAL | 9.9 | 2026-08-24 | A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite… | |
| CVE-2026-78169 | CRITICAL | 9.9 | 2026-08-24 | A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HT… | |
| CVE-2026-78155 | CRITICAL | 9.9 | 2026-08-23 | privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges | |
| CVE-2026-78050 | CRITICAL | 9.9 | 2026-08-23 | A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezone of th… | |
| CVE-2026-62283 | CRITICAL | Patched | 9.9 | 2026-08-21 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind s… |