Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 201–225 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-78327 CRITICAL 9.1 2026-09-04 An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Manageme…
CVE-2026-78328 CRITICAL 9.1 2026-09-04 A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileg…
CVE-2026-75431 CRITICAL 9.1 2026-09-04 PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code.
CVE-2026-75160 CRITICAL 9.1 2026-09-04 An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.
CVE-2026-85684 CRITICAL 9.1 2026-09-04 marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attac…
CVE-2026-85667 CRITICAL 9.1 2026-09-04 xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into t…
CVE-2026-85184 CRITICAL Patched 9.1 2026-09-04 @fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolve…
CVE-2026-85430 CRITICAL 9.1 2026-09-03 MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attack…
CVE-2026-85434 CRITICAL 9.1 2026-09-03 MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with …
CVE-2026-85435 CRITICAL 9.1 2026-09-03 MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shor…
CVE-2026-62916 CRITICAL 9.1 2026-09-03 Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-85224 CRITICAL 9.1 2026-09-03 A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executin…
CVE-2026-85222 CRITICAL 9.1 2026-09-03 A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component…
CVE-2026-85043 CRITICAL 9.1 2026-09-03 Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium …
CVE-2026-85394 CRITICAL 9.1 2026-09-03 python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attacker…
CVE-2026-58400 CRITICAL Patched 9.1 2026-09-03 GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is con…
CVE-2026-66786 CRITICAL 9.1 2026-09-02 A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper va…
CVE-2026-73475 CRITICAL Patched 9.1 2026-09-02 Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.
CVE-2026-84699 CRITICAL Patched 9.1 2026-09-02 Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local acc…
CVE-2026-84479 CRITICAL 9.1 2026-09-01 WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoM…
CVE-2026-84639 CRITICAL Patched 9.1 2026-09-01 Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and T…
CVE-2026-18931 CRITICAL 9.1 2026-09-01 Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Retrieve Embedded Sensitive Data. Th…
CVE-2026-51743 CRITICAL 9.1 2026-09-01 Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via se…
CVE-2026-50093 CRITICAL 9.0 2026-09-08 A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Co&hellip;
CVE-2026-66768 CRITICAL 9.0 2026-09-08 SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit th&hellip;