Search
13,088 CVEs
CVEs (13,088, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 151–175 of 13,088 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77810 | CRITICAL | Patched | 9.9 | 2026-08-21 | In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector… |
| CVE-2026-62867 | CRITICAL | 9.9 | 2026-08-21 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration… | |
| CVE-2026-62940 | CRITICAL | 9.9 | 2026-08-21 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides… | |
| CVE-2026-62941 | CRITICAL | 9.9 | 2026-08-21 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCrea… | |
| CVE-2026-63125 | CRITICAL | 9.9 | 2026-08-21 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_creat… | |
| CVE-2026-63343 | CRITICAL | Patched | 9.9 | 2026-08-21 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path a… |
| CVE-2026-48755 | CRITICAL | 9.9 | 2026-08-21 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injecti… | |
| CVE-2026-48769 | CRITICAL | 9.9 | 2026-08-21 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a … | |
| CVE-2026-48749 | CRITICAL | 9.9 | 2026-08-21 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; … | |
| CVE-2026-48750 | CRITICAL | 9.9 | 2026-08-21 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of … | |
| CVE-2026-48751 | CRITICAL | 9.9 | 2026-08-21 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for … | |
| CVE-2026-48752 | CRITICAL | 9.9 | 2026-08-21 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary … | |
| CVE-2026-48753 | CRITICAL | 9.9 | 2026-08-21 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbi… | |
| CVE-2026-77683 | CRITICAL | 9.9 | 2026-08-21 | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezo… | |
| CVE-2026-69851 | CRITICAL | 9.9 | 2026-08-20 | Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-68782 | CRITICAL | 9.9 | 2026-08-20 | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-68789 | CRITICAL | 9.9 | 2026-08-20 | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-63509 | CRITICAL | 9.9 | 2026-08-20 | Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-18835 | CRITICAL | Patched | 9.9 | 2026-08-20 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements u… |
| CVE-2026-67567 | CRITICAL | 9.9 | 2026-08-20 | A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), t… | |
| CVE-2026-77148 | CRITICAL | 9.9 | 2026-08-20 | A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET§ion=ptest_channel of the componen… | |
| CVE-2026-77022 | CRITICAL | 9.9 | 2026-08-20 | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_… | |
| CVE-2026-74014 | CRITICAL | 9.9 | 2026-08-20 | Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions. | |
| CVE-2026-74016 | CRITICAL | 9.9 | 2026-08-20 | Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions. | |
| CVE-2026-74018 | CRITICAL | 9.9 | 2026-08-20 | Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions. |