Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 176–200 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-84813 CRITICAL 9.3 2026-09-03 Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.
CVE-2026-84768 CRITICAL 9.3 2026-09-03 Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.
CVE-2026-85183 CRITICAL 9.3 2026-09-03 Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim&hellip;
CVE-2026-80726 CRITICAL 9.3 2026-09-03 In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page Explicitly clear role.inva&hellip;
CVE-2026-78080 NONE &mdash; 2026-09-03 Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used in queries without validation, allowing SQLi vectors.
CVE-2026-53670 NONE Patched &mdash; 2026-09-02 PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, in the Prevail eBPF verifier, EbpfTransformer::add() silently &hellip;
CVE-2026-53671 NONE Patched &mdash; 2026-09-02 PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the abstract transformer in prevail treats writes through a T_&hellip;
CVE-2026-81286 CRITICAL 9.3 2026-09-02 Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.
CVE-2026-78319 NONE &mdash; 2026-09-01 A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition. An unauthenticated remote attacker could exploit this rac&hellip;
CVE-2026-86426 NONE Patched &mdash; 2026-09-07 LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeri&hellip;
CVE-2026-86060 NONE Patched &mdash; 2026-09-05 RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask &hellip;
CVE-2026-67276 NONE Patched &mdash; 2026-09-05 RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting &hellip;
CVE-2026-67402 NONE &mdash; 2026-09-04 An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated att&hellip;
CVE-2026-76178 NONE &mdash; 2026-09-03 A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification. A user with administrator p&hellip;
CVE-2026-9621 NONE &mdash; 2026-09-01 A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the &hellip;
CVE-2026-84149 NONE &mdash; 2026-09-01 This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could&hellip;
CVE-2026-84148 NONE &mdash; 2026-09-01 This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit &hellip;
CVE-2026-86542 CRITICAL Patched 9.1 2026-09-07 knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can sup&hellip;
CVE-2026-86153 CRITICAL 9.1 2026-09-06 A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation lead&hellip;
CVE-2026-86151 CRITICAL 9.1 2026-09-06 A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Mana&hellip;
CVE-2026-86148 CRITICAL 9.1 2026-09-05 A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipu&hellip;
CVE-2026-86149 CRITICAL 9.1 2026-09-05 A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument inte&hellip;
CVE-2026-86190 CRITICAL 9.1 2026-09-05 WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and li&hellip;
CVE-2026-52766 CRITICAL Patched 9.1 2026-09-05 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array fro&hellip;
CVE-2026-81939 CRITICAL 9.1 2026-09-04 A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outsid&hellip;