Search
34,865 CVEs · Critical severity
CVEs (34,865, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 201–225 of 34,865 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-51743 | CRITICAL | 9.1 | 2026-09-01 | Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via se… | |
| CVE-2026-51744 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronizati… | |
| CVE-2026-51747 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh heartbeat information toward … | |
| CVE-2026-18765 | CRITICAL | 9.8 | 2026-09-01 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This … | |
| CVE-2026-84200 | CRITICAL | Patched | 9.0 | 2026-09-01 | Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive … |
| CVE-2026-18550 | CRITICAL | 9.8 | 2026-09-01 | The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to i… | |
| CVE-2026-83772 | CRITICAL | 9.9 | 2026-09-01 | A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-repor… | |
| CVE-2026-75865 | CRITICAL | 9.8 | 2026-09-01 | The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing… | |
| CVE-2026-82971 | CRITICAL | 10.0 | 2026-08-31 | A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This mani… | |
| CVE-2026-83524 | CRITICAL | 9.9 | 2026-08-31 | A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file … | |
| CVE-2026-82954 | CRITICAL | 9.9 | 2026-08-31 | A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts … | |
| CVE-2026-82226 | CRITICAL | 9.8 | 2026-08-31 | Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions. | |
| CVE-2026-81780 | CRITICAL | 10.0 | 2026-08-31 | Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. | |
| CVE-2026-81763 | CRITICAL | 9.3 | 2026-08-31 | Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions. | |
| CVE-2026-81779 | CRITICAL | 10.0 | 2026-08-31 | Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0… | |
| CVE-2026-81293 | CRITICAL | 9.3 | 2026-08-31 | Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions. | |
| CVE-2026-81756 | CRITICAL | 9.3 | 2026-08-31 | Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. | |
| CVE-2026-79408 | CRITICAL | 9.8 | 2026-08-31 | An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt… | |
| CVE-2026-38577 | CRITICAL | 9.8 | 2026-08-31 | Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access. | |
| CVE-2026-51738 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset the device configuration and reboot … | |
| CVE-2026-51740 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a craf… | |
| CVE-2026-51731 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST … | |
| CVE-2026-51733 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending … | |
| CVE-2026-51734 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh slave update coordination v… | |
| CVE-2026-51736 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST r… |