Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

196 CVEs · Critical severity

CVEs (196)

Showing 1–25 of 196

CVE ID Severity Patch CVSS Published Description
CVE-2026-50093 CRITICAL 9.0 2026-09-08 A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Co&hellip;
CVE-2026-66768 CRITICAL 9.0 2026-09-08 SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit th&hellip;
CVE-2026-84803 CRITICAL 9.0 2026-09-02 SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. A&hellip;
CVE-2026-84324 CRITICAL Patched 9.0 2026-09-02 Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromi&hellip;
CVE-2026-75604 CRITICAL Patched 9.0 2026-09-01 Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without C&hellip;
CVE-2026-73700 CRITICAL Patched 9.0 2026-09-01 A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-s&hellip;
CVE-2026-73701 CRITICAL Patched 9.0 2026-09-01 An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain precond&hellip;
CVE-2026-79687 CRITICAL 9.0 2026-09-01 Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this v&hellip;
CVE-2026-84200 CRITICAL Patched 9.0 2026-09-01 Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive &hellip;
CVE-2026-86542 CRITICAL Patched 9.1 2026-09-07 knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can sup&hellip;
CVE-2026-86153 CRITICAL 9.1 2026-09-06 A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation lead&hellip;
CVE-2026-86151 CRITICAL 9.1 2026-09-06 A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Mana&hellip;
CVE-2026-86148 CRITICAL 9.1 2026-09-05 A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipu&hellip;
CVE-2026-86149 CRITICAL 9.1 2026-09-05 A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument inte&hellip;
CVE-2026-86190 CRITICAL 9.1 2026-09-05 WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and li&hellip;
CVE-2026-52766 CRITICAL Patched 9.1 2026-09-05 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array fro&hellip;
CVE-2026-81939 CRITICAL 9.1 2026-09-04 A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outsid&hellip;
CVE-2026-78327 CRITICAL 9.1 2026-09-04 An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Manageme&hellip;
CVE-2026-78328 CRITICAL 9.1 2026-09-04 A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileg&hellip;
CVE-2026-75431 CRITICAL 9.1 2026-09-04 PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code.
CVE-2026-75160 CRITICAL 9.1 2026-09-04 An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.
CVE-2026-85684 CRITICAL 9.1 2026-09-04 marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attac&hellip;
CVE-2026-85667 CRITICAL 9.1 2026-09-04 xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into t&hellip;
CVE-2026-85184 CRITICAL Patched 9.1 2026-09-04 @fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolve&hellip;
CVE-2026-85430 CRITICAL 9.1 2026-09-03 MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attack&hellip;