Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

34,865 CVEs · Critical severity

CVEs (34,865, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 151–175 of 34,865 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-85509 CRITICAL Patched 9.8 2026-09-04 FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.
CVE-2026-85508 CRITICAL Patched 9.8 2026-09-04 ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell…
CVE-2026-85507 CRITICAL Patched 9.8 2026-09-04 ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).
CVE-2026-85506 CRITICAL Patched 9.8 2026-09-04 ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-syst…
CVE-2026-85504 CRITICAL Patched 9.8 2026-09-04 FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malfo…
CVE-2026-85440 CRITICAL 9.8 2026-09-03 MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling that allows remote attackers to write arbitrary data …
CVE-2026-85438 CRITICAL 9.8 2026-09-03 MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used a…
CVE-2026-85437 CRITICAL 9.8 2026-09-03 MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust attacker-controlled length fields without validation. A…
CVE-2026-85435 CRITICAL 9.1 2026-09-03 MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shor…
CVE-2026-85434 CRITICAL 9.1 2026-09-03 MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with …
CVE-2026-85433 CRITICAL 9.8 2026-09-03 MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. At…
CVE-2026-85430 CRITICAL 9.1 2026-09-03 MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attack…
CVE-2026-85428 CRITICAL 9.8 2026-09-03 MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Att…
CVE-2026-85426 CRITICAL 9.8 2026-09-03 MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into clie…
CVE-2026-85425 CRITICAL 9.8 2026-09-03 MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsanitized text to a shell command. Attackers can …
CVE-2026-85424 CRITICAL 9.8 2026-09-03 MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privil…
CVE-2026-85394 CRITICAL 9.1 2026-09-03 python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attacker…
CVE-2026-85391 CRITICAL 9.8 2026-09-03 Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attack…
CVE-2026-85224 CRITICAL 9.1 2026-09-03 A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executin…
CVE-2026-85223 CRITICAL 9.9 2026-09-03 A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Pe…
CVE-2026-85222 CRITICAL 9.1 2026-09-03 A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component…
CVE-2026-85184 CRITICAL Patched 9.1 2026-09-04 @fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolve…
CVE-2026-85183 CRITICAL 9.3 2026-09-03 Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim…
CVE-2026-85181 CRITICAL 9.8 2026-09-03 CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can…
CVE-2026-85154 CRITICAL 9.8 2026-09-03 WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator…