Search
208 CVEs · Critical severity
CVEs (208)
Showing 1–25 of 208
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9055 | CRITICAL | 9.8 | 2026-09-02 | The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insuf… | |
| CVE-2026-86543 | CRITICAL | Patched | 9.8 | 2026-09-07 | knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attack… |
| CVE-2026-86542 | CRITICAL | Patched | 9.1 | 2026-09-07 | knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can sup… |
| CVE-2026-86510 | CRITICAL | 9.9 | 2026-09-08 | A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to… | |
| CVE-2026-86509 | CRITICAL | 9.6 | 2026-09-08 | A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulati… | |
| CVE-2026-86480 | CRITICAL | Patched | 9.8 | 2026-09-07 | In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges |
| CVE-2026-86478 | CRITICAL | Patched | 9.8 | 2026-09-07 | In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address |
| CVE-2026-86299 | CRITICAL | 9.9 | 2026-09-07 | A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Ha… | |
| CVE-2026-86296 | CRITICAL | 10.0 | 2026-09-07 | A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This ma… | |
| CVE-2026-86190 | CRITICAL | 9.1 | 2026-09-05 | WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and li… | |
| CVE-2026-86189 | CRITICAL | 9.8 | 2026-09-05 | WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a cal… | |
| CVE-2026-86184 | CRITICAL | Patched | 9.8 | 2026-09-05 | Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user … |
| CVE-2026-86167 | CRITICAL | 9.9 | 2026-09-06 | A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation… | |
| CVE-2026-86165 | CRITICAL | 9.8 | 2026-09-06 | A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argu… | |
| CVE-2026-86153 | CRITICAL | 9.1 | 2026-09-06 | A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation lead… | |
| CVE-2026-86152 | CRITICAL | 10.0 | 2026-09-06 | A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. … | |
| CVE-2026-86151 | CRITICAL | 9.1 | 2026-09-06 | A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Mana… | |
| CVE-2026-86149 | CRITICAL | 9.1 | 2026-09-05 | A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument inte… | |
| CVE-2026-86148 | CRITICAL | 9.1 | 2026-09-05 | A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipu… | |
| CVE-2026-86124 | CRITICAL | 9.8 | 2026-09-05 | AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. At… | |
| CVE-2026-86121 | CRITICAL | Patched | 9.8 | 2026-09-05 | Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthe… |
| CVE-2026-85696 | CRITICAL | 9.8 | 2026-09-04 | SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper esc… | |
| CVE-2026-85695 | CRITICAL | 9.4 | 2026-09-04 | FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and p… | |
| CVE-2026-85688 | CRITICAL | 9.8 | 2026-09-04 | TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and … | |
| CVE-2026-85684 | CRITICAL | 9.1 | 2026-09-04 | marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attac… |