Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 176–200 of 2,372 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84813 | CRITICAL | 9.3 | 2026-09-03 | Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions. | |
| CVE-2026-84768 | CRITICAL | 9.3 | 2026-09-03 | Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions. | |
| CVE-2026-85183 | CRITICAL | 9.3 | 2026-09-03 | Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim… | |
| CVE-2026-80726 | CRITICAL | 9.3 | 2026-09-03 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page Explicitly clear role.inva… | |
| CVE-2026-78080 | NONE | — | 2026-09-03 | Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used in queries without validation, allowing SQLi vectors. | |
| CVE-2026-53670 | NONE | Patched | — | 2026-09-02 | PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, in the Prevail eBPF verifier, EbpfTransformer::add() silently … |
| CVE-2026-53671 | NONE | Patched | — | 2026-09-02 | PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the abstract transformer in prevail treats writes through a T_… |
| CVE-2026-81286 | CRITICAL | 9.3 | 2026-09-02 | Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions. | |
| CVE-2026-78319 | NONE | — | 2026-09-01 | A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition. An unauthenticated remote attacker could exploit this rac… | |
| CVE-2026-86426 | NONE | Patched | — | 2026-09-07 | LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeri… |
| CVE-2026-86060 | NONE | Patched | — | 2026-09-05 | RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask … |
| CVE-2026-67276 | NONE | Patched | — | 2026-09-05 | RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting … |
| CVE-2026-67402 | NONE | — | 2026-09-04 | An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated att… | |
| CVE-2026-76178 | NONE | — | 2026-09-03 | A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification. A user with administrator p… | |
| CVE-2026-9621 | NONE | — | 2026-09-01 | A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the … | |
| CVE-2026-84149 | NONE | — | 2026-09-01 | This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could… | |
| CVE-2026-84148 | NONE | — | 2026-09-01 | This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit … | |
| CVE-2026-86542 | CRITICAL | Patched | 9.1 | 2026-09-07 | knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can sup… |
| CVE-2026-86153 | CRITICAL | 9.1 | 2026-09-06 | A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation lead… | |
| CVE-2026-86151 | CRITICAL | 9.1 | 2026-09-06 | A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Mana… | |
| CVE-2026-86148 | CRITICAL | 9.1 | 2026-09-05 | A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipu… | |
| CVE-2026-86149 | CRITICAL | 9.1 | 2026-09-05 | A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument inte… | |
| CVE-2026-86190 | CRITICAL | 9.1 | 2026-09-05 | WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and li… | |
| CVE-2026-52766 | CRITICAL | Patched | 9.1 | 2026-09-05 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array fro… |
| CVE-2026-81939 | CRITICAL | 9.1 | 2026-09-04 | A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outsid… |