Search
2,281 CVEs
EOL hidden · Show all products
CVEs (2,281, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 2,281 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44756 | CRITICAL | 10.0 | 2026-09-08 | A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a craf… | |
| CVE-2026-75650 | CRITICAL | 10.0 | 2026-09-07 | Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the co… | |
| CVE-2026-86296 | CRITICAL | 10.0 | 2026-09-07 | A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This ma… | |
| CVE-2026-86218 | NONE | Patched | — | 2026-09-06 | N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. |
| CVE-2026-86152 | CRITICAL | 10.0 | 2026-09-06 | A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. … | |
| CVE-2026-75754 | NONE | — | 2026-09-04 | Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obt… | |
| CVE-2026-70352 | CRITICAL | 10.0 | 2026-09-03 | Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-83711 | CRITICAL | 10.0 | 2026-09-03 | Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-85061 | CRITICAL | Patched | 10.0 | 2026-09-03 | MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap… |
| CVE-2026-4357 | CRITICAL | 10.0 | 2026-09-02 | The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for un… | |
| CVE-2026-83548 | CRITICAL | Patched | 10.0 | 2026-09-01 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker c… |
| CVE-2026-76658 | CRITICAL | Patched | 10.0 | 2026-09-01 | A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to… |
| CVE-2026-76657 | CRITICAL | Patched | 10.0 | 2026-09-01 | Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing aut… |
| CVE-2026-84147 | NONE | — | 2026-09-01 | This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attac… | |
| CVE-2026-86510 | CRITICAL | 9.9 | 2026-09-08 | A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to… | |
| CVE-2026-86299 | CRITICAL | 9.9 | 2026-09-07 | A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Ha… | |
| CVE-2026-79698 | CRITICAL | 9.9 | 2026-09-07 | A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-66… | |
| CVE-2026-79697 | CRITICAL | 9.9 | 2026-09-07 | A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-66… | |
| CVE-2026-86167 | CRITICAL | 9.9 | 2026-09-06 | A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation… | |
| CVE-2026-85223 | CRITICAL | 9.9 | 2026-09-03 | A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Pe… | |
| CVE-2026-85031 | CRITICAL | 9.9 | 2026-09-03 | A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument t… | |
| CVE-2026-77009 | CRITICAL | 9.9 | 2026-09-02 | The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user,… | |
| CVE-2026-83772 | CRITICAL | 9.9 | 2026-09-01 | A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-repor… | |
| CVE-2026-71376 | CRITICAL | Patched | 9.8 | 2026-09-08 | OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 1… |
| CVE-2026-71377 | CRITICAL | Patched | 9.8 | 2026-09-08 | Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 be… |