Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 126–150 of 2,372 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-51764 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking … | |
| CVE-2026-51765 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor recor… | |
| CVE-2026-51750 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channe… | |
| CVE-2026-51751 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local … | |
| CVE-2026-18808 | CRITICAL | 9.8 | 2026-09-01 | Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This i… | |
| CVE-2026-18210 | CRITICAL | Patched | 9.8 | 2026-09-01 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and T… |
| CVE-2026-84140 | CRITICAL | Patched | 9.8 | 2026-09-01 | Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-84141 | CRITICAL | Patched | 9.8 | 2026-09-01 | Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-84142 | CRITICAL | Patched | 9.8 | 2026-09-01 | Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enoug… |
| CVE-2026-84143 | CRITICAL | Patched | 9.8 | 2026-09-01 | Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another secur… |
| CVE-2026-84133 | CRITICAL | Patched | 9.8 | 2026-09-01 | Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-84134 | CRITICAL | Patched | 9.8 | 2026-09-01 | Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-84135 | CRITICAL | Patched | 9.8 | 2026-09-01 | Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155. |
| CVE-2026-84129 | CRITICAL | Patched | 9.8 | 2026-09-01 | Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-51741 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a craft… | |
| CVE-2026-51744 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronizati… | |
| CVE-2026-51747 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh heartbeat information toward … | |
| CVE-2026-18765 | CRITICAL | 9.8 | 2026-09-01 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This … | |
| CVE-2026-18550 | CRITICAL | 9.8 | 2026-09-01 | The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to i… | |
| CVE-2026-75865 | CRITICAL | 9.8 | 2026-09-01 | The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing… | |
| CVE-2026-86509 | CRITICAL | 9.6 | 2026-09-08 | A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulati… | |
| CVE-2026-75925 | CRITICAL | 9.6 | 2026-09-04 | Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by… | |
| CVE-2026-19274 | CRITICAL | 9.6 | 2026-09-04 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently dest… | |
| CVE-2026-85085 | CRITICAL | Patched | 9.6 | 2026-09-04 | The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to com… |
| CVE-2026-85050 | CRITICAL | 9.6 | 2026-09-03 | Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTM… |